Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2011-2244 Vulnerability (CVE-2011-2244)
WordPress Plugin IMPress for IDX Broker Multiple Vulnerabilities (2.6.1)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (4.1.5.2)
WordPress Plugin Catch Duplicate Switcher Security Bypass (1.5.2)
Python Files or Directories Accessible to External Parties Vulnerability (CVE-2019-13404)