CVE-2021-41236

    Dashboard / Vulnerabilities / CVE-2021-41236

    CVE-2021-41236

    Published: 4 Jan 2022Last Modified: 8 Jul 2026

    Summary:

    Details: OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must have permission to create or edit an email template. For successful payload, execution the attacked user must preview a vulnerable email template. There are no workarounds that address this vulnerability. Users are advised to upgrade as soon as is possible.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 02bffd6c9c5cef5a16916b4c96cd4fab109fb999

    Affected versions

    4.2.7
    4.2.6
    4.2.4
    4.2.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-41236 | CVE-DB