Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.
Remediation
References
Related Vulnerabilities
Nginx Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-1247)
WordPress Plugin LearnPress-WordPress LMS SQL Injection (4.1.3.2)
MySQL CVE-2024-21196 Vulnerability (CVE-2024-21196)
MySQL CVE-2021-2230 Vulnerability (CVE-2021-2230)
Atlassian Jira CVE-2021-39121 Vulnerability (CVE-2021-39121)