← Back

CVE-2019-12186

nvd nist
Published: Dec 31, 2019Modified: Nov 21, 2024

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x through 1.1.18, 1.2.x through 1.2.17, 1.3.x through 1.3.12, 1.4.x through 1.4.4, and 1.5.0 allows an attacker (an admin in the sylius/sylius case) to perform XSS by injecting malicious code into a field displayed in a grid with the "string" field type. The contents are an object, with malicious code returned by the __toString() method of that object.

Affected (11)

Products: Sylius: Grid, Sylius
2 products
Grid
Sylius
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Sylius
From 1.0.0 to 1.0.18
From 1.1.0 to 1.1.18
From 1.2.0 to 1.2.17
From 1.3.0 to 1.3.12
From 1.4.0 to 1.4.4
Version 1.5.0
Sylius
From 1.0.0 to 1.0.18
From 1.1.0 to 1.1.17
From 1.2.0 to 1.2.16
From 1.3.0 to 1.3.11
From 1.4.0 to 1.4.3

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.