Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.
Remediation
References
Related Vulnerabilities
WordPress Plugin CataBlog 'category' Parameter Cross-Site Scripting (1.6.2)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce SQL Injection (1.3.6)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.38)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29212)
XWiki Credentials Management Errors Vulnerability (CVE-2005-4862)