Description
In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2738 Vulnerability (CVE-2019-2738)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)
WordPress Plugin Animate It! Cross-Site Scripting (2.3.3)
Roundcube Resource Management Errors Vulnerability (CVE-2011-4078)
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (6.0.11)