Description
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the product catalog to inject malicious javascript.
Remediation
References
Related Vulnerabilities
WordPress Plugin Relocate Upload 'abspath' Parameter Remote File Include (0.14)
WordPress Plugin BulletProof Security Cross-Site Scripting (.52.4)
Oracle Database Server CVE-2012-1746 Vulnerability (CVE-2012-1746)
WordPress Plugin Cookie Bar Cross-Site Scripting (1.8.8)
WordPress Plugin Cryptocurrency Widgets For Elementor Security Bypass (1.2.1)