Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.
Remediation
References
Related Vulnerabilities
WordPress Plugin Daily Prayer Time Cross-Site Request Forgery (2023.03.08)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29203)
WordPress Plugin Add Comments Cross-Site Scripting (1.0.1)
MySQL CVE-2017-3467 Vulnerability (CVE-2017-3467)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1595)