CVE-2021-41236
XSS vulnerability in oro/platform
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must have permission to create or edit an email template. For successful payload, execution the attacked user must preview a vulnerable email template. There are no workarounds that address this vulnerability. Users are advised to upgrade as soon as is possible.
OroPlatform es una plataforma de aplicaciones empresariales en PHP. En las versiones afectadas, la vista previa de la plantilla de correo electrónico es vulnerable a una carga útil de tipo XSS añadida al contenido de la plantilla de correo electrónico. Un atacante debe tener permiso para crear o editar una plantilla de correo electrónico. Para que la carga útil sea ejecutada con éxito, el usuario atacado debe previsualizar una plantilla de correo electrónico vulnerable. No se presentan medidas de mitigación que aborden esta vulnerabilidad. Se aconseja a usuarios que actualicen lo antes posible
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-15 CVE Reserved
- 2022-01-04 CVE Published
- 2023-07-28 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/oroinc/platform/security/advisories/GHSA-qv7g-j98v-8pp7 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/oroinc/platform/commit/2a089c971fc70bc63baf8770d29ee515ce5a415a | 2022-01-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oroinc Search vendor "Oroinc" | Oroplatform Search vendor "Oroinc" for product "Oroplatform" | >= 3.1.0 < 3.1.21 Search vendor "Oroinc" for product "Oroplatform" and version " >= 3.1.0 < 3.1.21" | - |
Affected
| ||||||
Oroinc Search vendor "Oroinc" | Oroplatform Search vendor "Oroinc" for product "Oroplatform" | >= 4.1.0 < 4.1.14 Search vendor "Oroinc" for product "Oroplatform" and version " >= 4.1.0 < 4.1.14" | - |
Affected
| ||||||
Oroinc Search vendor "Oroinc" | Oroplatform Search vendor "Oroinc" for product "Oroplatform" | >= 4.2.0 < 4.2.8 Search vendor "Oroinc" for product "Oroplatform" and version " >= 4.2.0 < 4.2.8" | - |
Affected
|