Description
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
Remediation
References
Related Vulnerabilities
XWikiplatform Improper Encoding or Escaping of Output Vulnerability (CVE-2024-55663)
WordPress Plugin Advanced ads Management by Inazo Cross-Site Scripting (1.3)
Python Inefficient Regular Expression Complexity Vulnerability (CVE-2024-7592)
Oracle Application Server CVE-2008-3977 Vulnerability (CVE-2008-3977)