Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Inventory Manager Unspecified Vulnerability (1.8.1)
LimeSurvey Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-16174)
WordPress Plugin WP Easy Stats 'homep' Parameter Remote File Include (1.8)
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6338)