Description
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.
Remediation
References
Related Vulnerabilities
Moodle Other Vulnerability (CVE-2006-4937)
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4902)
OpenVPN AS Improper Authentication Vulnerability (CVE-2020-15077)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)
WordPress Plugin Weather Effect-Christmas Santa Snow Falling Cross-Site Scripting (1.3.5)