Description
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
Remediation
References
Related Vulnerabilities
Drupal Other Vulnerability (CVE-2015-3232)
WordPress Plugin qTranslate Cross-Site Request Forgery (2.5.34)
Oracle Database Server CVE-2015-0468 Vulnerability (CVE-2015-0468)
WordPress Plugin Bookly #1 WordPress Booking Plugin (Lite Version) Cross-Site Scripting (14.4)
WordPress Plugin All-in-One Event Calendar Multiple Cross-Site Scripting Vulnerabilities (1.5)