CVE-2021-41236
XSS vulnerability on email template preview page
6.9
MEDIUM
CVSS 3.1
EPSS 0.67%
Description
### Summary Email template preview is vulnerable to XSS payload added to email template content. The attacker should have permission to create or edit an email template. For successful payload, execution attacked user should preview a vulnerable email template. ### Workarounds There are no workarounds that address this vulnerability.
How to fix CVE-2021-41236
To remediate CVE-2021-41236, upgrade the affected package to a fixed version below.
- —upgrade to 3.1.21 or later
Is CVE-2021-41236 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.1.0, < 3.1.21
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N |