Description
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.
Remediation
References
Related Vulnerabilities
Plone CMS CVE-2017-1000483 Vulnerability (CVE-2017-1000483)
WordPress 3.9.x Prototype Pollution (3.9 - 3.9.35)
WordPress Plugin Gallery by BestWebSoft Cross-Site Scripting (4.4.9)
WordPress Plugin W3 Total Cache Server-Side Request Forgery (0.9.7.3)
WordPress Plugin Google Authenticator-Per User Prompt Timing Attack (0.6)