Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.
Remediation
References
Related Vulnerabilities
Magento CVE-2019-7928 Vulnerability (CVE-2019-7928)
MySQL CVE-2022-21256 Vulnerability (CVE-2022-21256)
WordPress Plugin Slider by 10Web-Responsive Image Slider Unspecified Vulnerability (1.1.9)
WordPress Plugin WooCommerce Unspecified Vulnerability (3.9.1)
WordPress Plugin Esponce QR Code Generator Cross-Site Scripting (1.4)