Description
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.
Remediation
References
Related Vulnerabilities
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2018-8011)
WebLogic CVE-2022-21262 Vulnerability (CVE-2022-21262)
IBM Lotus Domino web server Cross-Site Scripting vulnerabilities
Oracle Database Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5499)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-10002)