Description
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin SFBrowser 'sfbrowser.php' Arbitrary File Upload (1.4.5)
UAParser.js Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2021-4229)
Oracle Database Server CVE-2007-2114 Vulnerability (CVE-2007-2114)
WordPress Plugin Google Doc Embedder SQL Injection (2.5.14)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6112)