Description
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.
Remediation
References
Related Vulnerabilities
WordPress Plugin Cart66 Lite::WordPress Ecommerce Multiple Vulnerabilities (1.5.3)
WordPress Plugin Slimstat Analytics SQL Injection (5.0.4)
WordPress Plugin Easy Google Analytics for WordPress Cross-Site Request Forgery (1.6.0)
WordPress 4.8.x Cross-Domain Flash Injection Vulnerability (4.8 - 4.8.4)