Description
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2775 Vulnerability (CVE-2018-2775)
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3690)
Joomla! Core 1.6.x Cross-Site Scripting (1.6.0 - 1.6.5)
MyBB Improper Access Control Vulnerability (CVE-2016-9412)
WordPress Plugin Backup and Staging by WP Time Capsule Security Bypass (1.21.15)