Description
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript execution in the victim's browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google XML Sitemap for Videos Cross-Site Request Forgery (2.6.1)
WordPress Plugin Stripe Payment for WooCommerce Security Bypass (3.7.7)
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842)
WordPress Plugin miniOrange Discord Integration Security Bypass (2.1.5)