Medium severity5.4NVD Advisory· Published Nov 15, 2024· Updated Jun 17, 2026
CVE-2021-3841
CVE-2021-3841
Description
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sylius/syliusPackagist | < 1.9.10 | 1.9.10 |
sylius/syliusPackagist | >= 1.10.0, < 1.10.11 | 1.10.11 |
sylius/syliusPackagist | >= 1.11.0, < 1.11.2 | 1.11.2 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/sylius/sylius/commit/3da169e0c23e752974d74223cc536c29a2a82edcnvdPatchWEB
- github.com/advisories/GHSA-hhvr-2q69-4563ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3841ghsaADVISORY
- huntr.com/bounties/1625506791178-Sylius/SyliusnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.