Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
Piwigo Improper Access Control Vulnerability (CVE-2016-10084)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3558)
WordPress Plugin St-Daily-Tip Cross-Site Request Forgery (4.7)
MySQL Other Vulnerability (CVE-2012-5383)
FrontAccounting Multiple SQL Injection Vulnerabilities (CVE-2014-3973)