GHSA-qv7g-j98v-8pp7
Dashboard / Vulnerabilities / GHSA-qv7g-j98v-8pp7
Summary: XSS vulnerability on email template preview page
Details: ### Summary Email template preview is vulnerable to XSS payload added to email template content. The attacker should have permission to create or edit an email template. For successful payload, execution attacked user should preview a vulnerable email template. ### Workarounds There are no workarounds that address this vulnerability.
References: https://github.com/oroinc/platform/security/advisories/GHSA-qv7g-j98v-8pp7, https://nvd.nist.gov/vuln/detail/CVE-2021-41236, https://github.com/oroinc/platform/commit/2a089c971fc70bc63baf8770d29ee515ce5a415a, https://github.com/oroinc/platform
Affected packages
Package
Name: oro/platform
Purl: pkg:composer/oro/platform
Affected ranges
Type: ECOSYSTEM
Events:
