原始 OSV JSON{
"id": "GHSA-qv7g-j98v-8pp7",
"aliases": [
"CVE-2021-41236"
],
"details": "### Summary\n\nEmail template preview is vulnerable to XSS payload added to email template content. The attacker should have permission to create or edit an email template. For successful payload, execution attacked user should preview a vulnerable email template.\n\n### Workarounds\n\nThere are no workarounds that address this vulnerability.",
"summary": "XSS vulnerability on email template preview page",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.1.0"
},
{
"fixed": "3.1.21"
}
]
}
],
"package": {
"name": "oro/platform",
"ecosystem": "Packagist"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.14"
}
]
}
],
"package": {
"name": "oro/platform",
"ecosystem": "Packagist"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.2.0"
},
{
"fixed": "4.2.8"
}
]
}
],
"package": {
"name": "oro/platform",
"ecosystem": "Packagist"
}
}
],
"modified": "2022-01-04T17:51:41Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"
}
],
"published": "2022-01-06T18:34:35Z",
"references": [
{
"url": "https://github.com/oroinc/platform/security/advisories/GHSA-qv7g-j98v-8pp7",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41236",
"type": "ADVISORY"
},
{
"url": "https://github.com/oroinc/platform/commit/2a089c971fc70bc63baf8770d29ee515ce5a415a",
"type": "WEB"
},
{
"url": "https://github.com/oroinc/platform",
"type": "PACKAGE"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2022-01-04T19:15:00Z",
"github_reviewed_at": "2022-01-04T17:51:41Z"
}
}