Stored Cross-Site Scripting (XSS) flaws in Magento allow attackers to hijack e-commerce websites. The bugs are quite easy to exploit. All an attacker need to do is embed malicious JavaScript code inside customer registration forms in place of email address. The bug is located inside Magento core libraries, more specifically within the administrator’s backend. An update has been made available to the public after security firm Sucuri discovered and privately reported the vulnerability to the company. The latest patch resolves the issue for Magento version 1.14.2.1 and 1.9.1.
Source: https://thehackernews.com/2016/01/magento-security.html