The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.