CVE-2021-39217

HIGH7.2EPSS 0.72%

Fix for arbitrary command execution in custom layout update through blocks

Published: 1/27/2023Modified: 3/14/2026
Also known as:GHSA-c9q3-r4rv-mjm7

Description

### Impact Custom Layout enabled admin users to execute arbitrary commands via block methods.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (6)