Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-0488 Vulnerability (CVE-2012-0488)
WordPress Plugin SyntaxHighlighter Evolved Cross-Site Scripting (3.1.9)
WordPress Plugin Filter Custom Fields & Taxonomies Light Unspecified Vulnerability (1.04)
Squid Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2021-28652)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-41524)