CVE-2021-3841

MEDIUM4.1EPSS 0.15%

Cross site scripting in sylius/sylius

Published: 11/15/2024Modified: 11/15/2024
Also known as:GHSA-hhvr-2q69-4563

Description

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.1CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

References (4)