Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.
Remediation
References
Related Vulnerabilities
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3170)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-1000353)
Oracle Database Server CVE-2006-0290 Vulnerability (CVE-2006-0290)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.8.9)
WordPress Plugin History Collection Arbitrary File Download (1.1.1)