A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
{
"extracted_events": [
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.18"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.9"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
],
"cpe": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
"source": "CPE_FIELD"
}