Description
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the Return Product comments field can inject malicious javascript.
Remediation
References
Related Vulnerabilities
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Scripting (1.3.1)
WordPress Plugin WordPress Meta Robots SQL Injection (2.1)
WordPress Plugin WP DSGVO Tools (GDPR) PHP Object Injection (2.0.4)
Ruby CVE-2018-16396 Vulnerability (CVE-2018-16396)
WordPress Plugin ABC Test 'id' Parameter Cross-Site Scripting (0.1)