Description
in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email template.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-6496 Vulnerability (CVE-2014-6496)
PHP Other Vulnerability (CVE-2002-2214)
WordPress Plugin Simple Slideshow Manager Multiple Cross-Site Scripting Vulnerabilities (2.3)
Apache Tomcat Improper Privilege Management Vulnerability (CVE-2020-1938)
WordPress Plugin ThemeHigh WooCommerce Wishlist and Comparison Cross-Site Request Forgery (1.0.4)