Description
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to email templates.
Remediation
References
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2012-6073)
WordPress Plugin Search & Replace SQL Injection (3.2.1)
Python Uncontrolled Resource Consumption Vulnerability (CVE-2022-45061)
WordPress Plugin Age Gate Unspecified Vulnerability (2.18.5)
ownCloud Improper Authentication Vulnerability (CVE-2014-9045)