Description
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Remediation
References
Related Vulnerabilities
WordPress Plugin Link Library Cross-Site Scripting (5.9.12.29)
Squid Insufficient Verification of Data Authenticity Vulnerability (CVE-2016-4554)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17302)
Joomla Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-15697)