#VU18095 Code injection in Magento Open Source
Published: March 30, 2019
Magento Open Source
Adobe
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient sanitization of user-supplied data when creating or editing newsletter or email templates. A remote authenticated user with privileges to create newsletter or email templates can inject and execute arbitrary PHP code on the system.