Description
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Calls to Action Multiple Cross-Site Scripting Vulnerabilities (2.5.0)
OpenSSL Inadequate Encryption Strength Vulnerability (CVE-2014-0224)
PHP Other Vulnerability (CVE-2002-0253)
CrushFTP Server Deserialization of Untrusted Data Vulnerability (CVE-2017-14035)
WordPress Plugin HTML5 AV Manager for WordPress 'custom.php' Arbitrary File Upload (0.2.7)