Magento CVE-2019-8231 Vulnerability (CVE-2019-8231)
Description
In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.