Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
Remediation
References
Related Vulnerabilities
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2023-26117)
Apache 2.x version older than 2.0.55
Joomla! Core 3.x.x Race Condition (3.0.0 - 3.8.7)
Oracle Database Server CVE-2008-0349 Vulnerability (CVE-2008-0349)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7888)