Description
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
Remediation
References
Related Vulnerabilities
XWiki Improper Handling of Insufficient Privileges Vulnerability (CVE-2024-21648)
WordPress Plugin PHP Speedy 'admin_container.php' Remote PHP Code Execution (0.5.2)
Ruby on Rails CVE-2018-16477 Vulnerability (CVE-2018-16477)
WordPress 'blog.header.php' Multiple SQL Injection Vulnerabilities (0.6.2 - 0.71)