Описание
Duplicate Advisory: Sylius Cross Site Scripting (XSS) vulnerability
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7prj-9ccr-hr3q. This link is maintained to preserve external references.
Original Description
Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
Пакеты
Наименование
sylius/sylius
composer
Затронутые версииВерсия исправления
<= 1.12.13
Отсутствует
5.4 Medium
CVSS3
Дефекты
CWE-79
5.4 Medium
CVSS3
Дефекты
CWE-79