Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.
Remediation
References
Related Vulnerabilities
WordPress Plugin Delete All Comments Easily Cross-Site Request Forgery (1.3)
WordPress Plugin Related Posts Multiple Cross-Site Request Forgery Vulnerabilities (1.0)
WordPress Plugin Thrive Ovation Security Bypass (2.4.4)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.10)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2242)