Description
An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request to perform arbitrary file deletion.
Remediation
References
Related Vulnerabilities
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20415)
PHP Other Vulnerability (CVE-2007-1475)
WordPress Plugin WP-Matomo (WP-Piwik) Cross-Site Scripting (1.0.10)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0702)
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000391)