Description
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manage orders can inject malicious javascript.
Remediation
References
Related Vulnerabilities
PHP Integer Overflow or Wraparound Vulnerability (CVE-2024-11236)
Drupal Core 9.4.x Security Bypass (9.4.0 - 9.4.2)
PostgreSQL Other Vulnerability (CVE-2006-0678)
Oracle Database Server CVE-2018-2939 Vulnerability (CVE-2018-2939)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-0195)