Description
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that specifies product design update.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Forms for MailChimp Unspecified Vulnerability (6.0.3.2)
WordPress Plugin Google Adsense and Hotel Booking Open Proxy (1.0.5)
WordPress 4.6.x Cross-Site Request Forgery (4.6 - 4.6.13)
WordPress Plugin GiveWP-Donation and Fundraising Platform PHP Object Injection (2.3.0)
WordPress Plugin Restricted Site Access Security Bypass (7.3.1)