Description
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the Return Product comments field can inject malicious javascript.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tajer Arbitrary File Upload (1.0.5)
Oracle Database Server CVE-2023-22074 Vulnerability (CVE-2023-22074)
WordPress Plugin Featured Posts by BestWebSoft Cross-Site Scripting (1.0.0)
Oracle Application Server CVE-2007-5526 Vulnerability (CVE-2007-5526)
WordPress Plugin Facebook, Twitter & Google+ Social Widgets Multiple Vulnerabilities (1.3.7)