VDB
Sign up
MEDIUM6.9

GHSA-qv7g-j98v-8pp7

XSS vulnerability on email template preview page

Quick fix

GHSA-qv7g-j98v-8pp7 — oro/platform: upgrade to the fixed version with the command below.

composer require oro/platform:^3.1.21

Details

### Summary

Email template preview is vulnerable to XSS payload added to email template content. The attacker should have permission to create or edit an email template. For successful payload, execution attacked user should preview a vulnerable email template.

### Workarounds

There are no workarounds that address this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oro/platform
Introduced in: 3.1.0Fixed in: 3.1.21
Fixcomposer require oro/platform:^3.1.21
Packagist/oro/platform
Introduced in: 4.1.0Fixed in: 4.1.14
Fixcomposer require oro/platform:^4.1.14
Packagist/oro/platform
Introduced in: 4.2.0Fixed in: 4.2.8
Fixcomposer require oro/platform:^4.2.8

References