Description
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.
Remediation
References
Related Vulnerabilities
Claroline Other Vulnerability (CVE-2005-1375)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2011-1134)
PostgreSQL Numeric Errors Vulnerability (CVE-2007-4769)
WordPress Plugin Post Views Counter Cross-Site Scripting (1.3.4)
WordPress Plugin Relevanssi-A Better Search Cross-Site Scripting (4.0.4)