Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
Remediation
References
Related Vulnerabilities
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42127)
PHP Use After Free Vulnerability (CVE-2019-13224)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4284)
Claroline Other Vulnerability (CVE-2006-1596)
WordPress Plugin Sticky Related Posts Cross-Site Scripting (1.0)