Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw82-6m2g-qh6c

Опубликовано: 22 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Duplicate Advisory: Sylius Cross Site Scripting (XSS) vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7prj-9ccr-hr3q. This link is maintained to preserve external references.

Original Description

Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

Пакеты

Наименование

sylius/sylius

composer
Затронутые версииВерсия исправления

<= 1.12.13

Отсутствует

5.4 Medium

CVSS3

Дефекты

CWE-79

5.4 Medium

CVSS3

Дефекты

CWE-79