Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Request Forgery (1.0.16)
WordPress Plugin YITH WooCommerce Subscription Security Bypass (1.3.4)
WordPress Plugin Social Networking & E-commerce Arbitrary File Upload (0.0.32)
WordPress Plugin PhotoXhibit Multiple Cross-Site Scripting Vulnerabilities (2.1.8)
WordPress Plugin Donorbox-Free Recurring Donation Form Cross-Site Scripting (7.1.1)