CVE-2021-3841 MEDIUM

CVE-2021-3841: Stored Cross-site Scripting (XSS) in sylius/sylius

Vendor Sylius
Product sylius/sylius
Weakness CWE-79 · XSS
Published November 15, 2024
Last update November 20, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.

Key dates

02Disclosure timeline

November 15, 2024 CVE published
November 20, 2024 Record updated