Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP FullCalendar Security Bypass (1.4.1)
Oracle JRE CVE-2012-3216 Vulnerability (CVE-2012-3216)
WordPress Plugin VikRentCar Car Rental Management System Cross-Site Scripting (1.1.9)
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.4.6)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2021-21019)