Description
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with permissions to manage customer groups.
Remediation
References
Related Vulnerabilities
WordPress CVE-2008-6767 Vulnerability (CVE-2008-6767)
WordPress Plugin Theme My Login 'instance' Parameter Cross-Site Scripting (6.1.4)
Python Improper Input Validation Vulnerability (CVE-2021-29921)
SharePoint CVE-2022-38053 Vulnerability (CVE-2022-38053)
WordPress Plugin Admin Font Editor Cross-Site Scripting (1.8)