Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.
Remediation
References
Related Vulnerabilities
Envoy Proxy Improper Authentication Vulnerability (CVE-2021-21378)
MySQL CVE-2015-0391 Vulnerability (CVE-2015-0391)
Oracle JRE CVE-2013-2439 Vulnerability (CVE-2013-2439)
WordPress Plugin WP eCommerce Multiple Unspecified Vulnerabilities (3.9.3)
Payara URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-7312)