Description
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Twenty20 Image Before-After Cross-Site Scripting (1.5.9)
WordPress Plugin WP Taxonomy Import Cross-Site Scripting (1.0.4)
Perl Other Vulnerability (CVE-2011-2728)
WordPress 2.0.3 Multiple Unspecified Security Vulnerabilities (2.0 - 2.0.3)
WordPress Plugin Stop User Enumeration Security Bypass (1.3.18)