Description
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
Remediation
References
Related Vulnerabilities
WordPress Plugin 3DPrint Cross-Site Request Forgery (3.5.4.7)
WordPress 5.8.x Directory Traversal (5.8 - 5.8.9)
Oracle Database Server CVE-2008-1817 Vulnerability (CVE-2008-1817)
WordPress Plugin Absolute Privacy 'abpr_authenticateUser()' Security Bypass (2.0.5)
WordPress Plugin W3SCloud Contact Form 7 to Zoho CRM Cross-Site Scripting (1.1.2)