Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP YouTube Live Cross-Site Scripting (1.7.21)
WordPress Plugin Currency Switcher for WooCommerce Security Bypass (2.11.1)
Jetty CVE-2023-40167 Vulnerability (CVE-2023-40167)
WordPress Plugin Verse-O-Matic Cross-Site Request Forgery (4.1.1)
WordPress Plugin .htaccess Redirect Cross-Site Scripting (0.3.1)