Description
In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1429)
PHP Safedir restriction bypass vulnerabilities
Python Numeric Errors Vulnerability (CVE-2008-2316)
Drupal Core 7.x Directory Traversal (7.0 - 7.66)
Artifactory Improper Privilege Management Vulnerability (CVE-2022-0668)