Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2782 Vulnerability (CVE-2018-2782)
Opencart Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3990)
MySQL CVE-2021-2087 Vulnerability (CVE-2021-2087)
Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-4729)
WordPress Plugin Slideshow Gallery LITE Cross-Site Scripting (1.5.3.4)