Description
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
Remediation
References
Related Vulnerabilities
Liferay Portal Other Vulnerability (CVE-2023-33947)
WordPress Plugin WP Activity Log PHP Object Injection (3.2.5)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4825)
Plone CMS Improper Input Validation Vulnerability (CVE-2011-4462)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-34467)