XSS injection in the Grid component of Sylius
Moderate severity
GitHub Reviewed
Published
Apr 15, 2020
to the GitHub Advisory Database
•
Updated Feb 26, 2024
Package
Affected versions
>= 1.0.0, < 1.1.19
>= 1.2.0, < 1.2.18
>= 1.3.0, < 1.3.13
>= 1.4.0, < 1.4.5
>= 1.5.0, < 1.5.1
Patched versions
1.1.19
1.2.18
1.3.13
1.4.5
1.5.1
>= 1.0.0, < 1.1.19
>= 1.2.0, < 1.2.18
>= 1.3.0, < 1.3.13
>= 1.4.0, < 1.4.5
>= 1.5.0, < 1.5.1
1.1.19
1.2.18
1.3.13
1.4.5
1.5.1
>= 1.0.0, < 1.1.18
>= 1.2.0, < 1.2.17
>= 1.3.0, < 1.3.12
>= 1.4.0, < 1.4.4
1.1.18
1.2.17
1.3.12
1.4.4
Description
Reviewed
Apr 15, 2020
Published to the GitHub Advisory Database
Apr 15, 2020
Last updated
Feb 26, 2024
Grid component of Sylius omits HTML input sanitisation while rendering object implementing __toString() method through the string field type.
References