Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
Remediation
References
Related Vulnerabilities
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.19)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2017-7671)
TYPO3 Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-26229)
Oracle Database Server CVE-2006-5336 Vulnerability (CVE-2006-5336)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.9.63)