VYPR
Moderate severityNVD Advisory· Published Apr 22, 2024· Updated Nov 22, 2024

CVE-2024-29376

CVE-2024-29376

Description

Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sylius/syliusPackagist
< 1.9.121.9.12
sylius/syliusPackagist
>= 1.10.0-alpha.1, < 1.10.161.10.16
sylius/syliusPackagist
>= 1.11.0-alpha.1, < 1.11.171.11.17
sylius/syliusPackagist
>= 1.12.0-alpha.1, < 1.12.161.12.16
sylius/syliusPackagist
>= 1.13.0-alpha.1, < 1.13.11.13.1

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.