An issue found in CraftCMS v.3.8.1 allows a remote malicious user to execute arbitrary code via a crafted script to the Section parameter.
craftcms craft cms 3.8.1