Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2009-1972 Vulnerability (CVE-2009-1972)
WordPress Plugin CSV Import Cross-Site Scripting (1.0)
WordPress Plugin HashBar-WordPress Notification Bar Cross-Site Scripting (1.3.5)
WordPress Plugin DW Question & Answer Cross-Site Scripting (1.4.2.2)
WordPress Plugin FB Survey Pro 'id' Parameter SQL Injection (1.0)