Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2021-2403 Vulnerability (CVE-2021-2403)
Microsoft SQL Server Improper Input Validation Vulnerability (CVE-1999-0999)
WordPress Plugin Nextend Google Connect Unspecified Vulnerability (1.5.3)
WordPress Plugin Monarch Social Sharing Security Bypass (1.2.6)
Squid Improper Input Validation Vulnerability (CVE-2014-3609)