Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.
Remediation
References
Related Vulnerabilities
Collabtive Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-5285)
WordPress Plugin iThemes Security (formerly Better WP Security) SQL Injection (7.0.2)
WordPress Plugin Enable Media Replace Directory Traversal (3.6.3)
MySQL CVE-2020-14777 Vulnerability (CVE-2020-14777)
OpenSSL Improper Access Control Vulnerability (CVE-2016-7054)