MEDIUM4.8
GHSA-rc5r-697f-28x6
XSS injection in the Grid component of Sylius
Quick fix
GHSA-rc5r-697f-28x6 — sylius/grid: upgrade to the fixed version with the command below.
composer require sylius/grid:^1.1.19Details
Grid component of Sylius omits HTML input sanitisation while rendering object implementing __toString() method through the string field type.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/sylius/grid-bundle
Introduced in:
1.0.0Fixed in: 1.1.19Fix
composer require sylius/grid-bundle:^1.1.19Packagist/sylius/grid-bundle
Introduced in:
1.2.0Fixed in: 1.2.18Fix
composer require sylius/grid-bundle:^1.2.18Packagist/sylius/grid-bundle
Introduced in:
1.3.0Fixed in: 1.3.13Fix
composer require sylius/grid-bundle:^1.3.13Packagist/sylius/grid-bundle
Introduced in:
1.4.0Fixed in: 1.4.5Fix
composer require sylius/grid-bundle:^1.4.5Packagist/sylius/grid-bundle
Introduced in:
1.5.0Fixed in: 1.5.1Fix
composer require sylius/grid-bundle:^1.5.1Packagist/sylius/sylius
Introduced in:
1.0.0Fixed in: 1.1.18Fix
composer require sylius/sylius:^1.1.18Packagist/sylius/sylius
Introduced in:
1.2.0Fixed in: 1.2.17Fix
composer require sylius/sylius:^1.2.17Packagist/sylius/sylius
Introduced in:
1.3.0Fixed in: 1.3.12Fix
composer require sylius/sylius:^1.3.12References
- https://nvd.nist.gov/vuln/detail/CVE-2019-12186[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/sylius/grid/CVE-2019-12186.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/sylius/sylius/CVE-2019-12186.yaml[WEB]
- https://sylius.com/blog/cve-2019-12186[WEB]