Description
A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2002-0121)
MySQL CVE-2021-2164 Vulnerability (CVE-2021-2164)
Apache Tomcat CVE-2017-5651 Vulnerability (CVE-2017-5651)
PostgreSQL Improper Certificate Validation Vulnerability (CVE-2012-0867)
WordPress Plugin Gallery-Flagallery Photo Portfolio 'skin' Parameter Cross-Site Scripting (1.72)