Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.
Remediation
References
Related Vulnerabilities
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49)
MySQL CVE-2020-2589 Vulnerability (CVE-2020-2589)
SharePoint Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5059)
TYPO3 CVE-2023-47126 Vulnerability (CVE-2023-47126)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3723)