Description
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.
Remediation
References
Related Vulnerabilities
PHP Numeric Errors Vulnerability (CVE-2008-4107)
WordPress Plugin FireDrum Email Marketing PHP Object Injection (1.47)
Joomla Missing Authorization Vulnerability (CVE-2020-10239)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3738)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-0541)