Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
Remediation
References
Related Vulnerabilities
Elgg Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3964)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2009-3294)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4792)
WordPress Plugin Gallery-Flagallery Photo Portfolio 'facebook.php' Cross-Site Scripting (1.56)