Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.
Remediation
References
Related Vulnerabilities
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4464)
WordPress Plugin Flo Forms-Easy Drag & Drop Form Builder Multiple Vulnerabilities (1.0.35)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4285)
WordPress Plugin Redirection Multiple Cross-Site Scripting Vulnerabilities (2.2.11)