Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-39402 Vulnerability (CVE-2022-39402)
Jenkins Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27901)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2272)
PostgreSQL Improper Control of Dynamically-Managed Code Resources Vulnerability (CVE-2022-2625)