Description
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` function and execute a malicious XSS payload.
Remediation
References
Related Vulnerabilities
WordPress Plugin yolink Search for WordPress Cross-Site Scripting (2.5)
WordPress Plugin AIT Themes-CSV Import/Export Arbitrary File Upload (3.0.3)
Oracle Database Server CVE-2006-3699 Vulnerability (CVE-2006-3699)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4421)
WordPress Plugin Leaflet Maps Marker Pro Multiple Vulnerabilities (1.5.7)