CVE-2021-3841
15.11.2024, 11:15
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.
Vendor | Product | Version |
---|---|---|
sylius | sylius | 𝑥 < 1.9.10 |
sylius | sylius | 1.10.0 ≤ 𝑥 < 1.10.11 |
sylius | sylius | 1.11.0 ≤ 𝑥 < 1.11.2 |
𝑥
= Vulnerable software versions