Description
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2019-2452 Vulnerability (CVE-2019-2452)
Apache Tomcat Other Vulnerability (CVE-2002-1567)
WordPress Plugin Top 10-Popular posts for WordPress SQL Injection (2.4.3)
WordPress Plugin Fileviewer Cross-Site Request Forgery (2.2)
PrestaShop Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-4792)