Description
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
Remediation
References
Related Vulnerabilities
Atlassian Jira Missing Authorization Vulnerability (CVE-2019-3399)
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)
PHP Numeric Errors Vulnerability (CVE-2010-4699)
SharePoint Out-of-bounds Write Vulnerability (CVE-2018-0792)
Apache Tomcat Improper Authentication Vulnerability (CVE-2011-5063)