Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Booking Calendar Multiple Vulnerabilities (6.2)
WordPress Plugin GA Universal Cross-Site Request Forgery (1.0)
WordPress Plugin Sliding Recent Posts Cross-Site Request Forgery (1.0)
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (1.10-standard)
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager SQL Injection (4.7.3)