| title: 'PRODSECBUG-2128: Stored Cross Site Scripting in the Admin Panel through the tax/notification/info_url setting'
link: 'https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-23'
cve: CVE-2019-7853
branches:
    '2.1':
        time: '2019-06-25 00:00:00'
        versions: ['>=2.1', '<2.1.18']
    '2.2':
        time: '2019-06-25 00:00:00'
        versions: ['>=2.2', '<2.2.9']
    '2.3':
        time: '2019-06-25 00:00:00'
        versions: ['>=2.3', '<2.3.2']
reference: 'composer://magento/product-community-edition'
composer-repository: false
 |