Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Affiliate Power-Sales Tracking for Affiliate Marketers Cross-Site Scripting (2.2.0)
Moodle Improper Input Validation Vulnerability (CVE-2020-1756)
WordPress Plugin Jibu Pro Cross-Site Scripting (1.7)
WordPress Plugin Digital River Global Commerce Supply Chain Attack [Polyfill.io] (2.0.2)