Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.
Remediation
References
Related Vulnerabilities
Zope Web Application Server Other Vulnerability (CVE-2000-0483)
WordPress Plugin Client Dash Cross-Site Scripting (2.1.4)
PleskWin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044)
WordPress Plugin aoringo LOG maker Cross-Site Scripting (0.1.3)
WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.6.2)