Medium severity6.9NVD Advisory· Published Jan 4, 2022· Updated Jun 17, 2026
CVE-2021-41236
CVE-2021-41236
Description
OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS payload added to email template content. An attacker must have permission to create or edit an email template. For successful payload, execution the attacked user must preview a vulnerable email template. There are no workarounds that address this vulnerability. Users are advised to upgrade as soon as is possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oro/platformPackagist | >= 3.1.0, < 3.1.21 | 3.1.21 |
oro/platformPackagist | >= 4.1.0, < 4.1.14 | 4.1.14 |
oro/platformPackagist | >= 4.2.0, < 4.2.8 | 4.2.8 |
Affected products
3- oroinc/platformv5Range: >= 3.1.0, < 3.1.21
Patches
Vulnerability mechanics
References
4- github.com/oroinc/platform/commit/2a089c971fc70bc63baf8770d29ee515ce5a415anvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-qv7g-j98v-8pp7ghsaADVISORY
- github.com/oroinc/platform/security/advisories/GHSA-qv7g-j98v-8pp7nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-41236ghsaADVISORY
News mentions
0No linked articles in our index yet.