Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
Remediation
References
Related Vulnerabilities
WordPress Plugin Shortcode Redirect 'domain' Parameter Cross-Site Scripting (1.0.01)
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.37)
Drupal Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2017-6928)