Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
MySQL CVE-2022-21285 Vulnerability (CVE-2022-21285)
MySQL CVE-2021-35644 Vulnerability (CVE-2021-35644)
WordPress Plugin WP Popups-WordPress Popup builder Cross-Site Scripting (2.1.4.6)
WordPress Plugin YITH WooCommerce Ajax Product Filter Cross-Site Scripting (3.11.0)