Description
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigger remote code execution.
Remediation
References
Related Vulnerabilities
WordPress Server-Side Request Forgery (3.7 - 6.1.1)
WordPress Plugin iQ Block Country Cross-Site Scripting (1.1.19)
WordPress Plugin Advanced Forms for ACF Security Bypass (1.6.8)
Oracle JRE CVE-2020-2754 Vulnerability (CVE-2020-2754)
WordPress Plugin WP FuneralPress Multiple Cross-Site Scripting Vulnerabilities (1.1.6)