Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20526
HistoryMar 15, 2022 - 12:00 a.m.

Sylius Cross-Site Scripting Vulnerability (CNVD-2022-20526)

2022-03-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
sylius
e-commerce
xss
vulnerability
administration panel
svg
phishing
cookies

EPSS

0.001

Percentile

41.3%

Sylius is an open source e-commerce platform. Sylius suffers from a cross-site scripting vulnerability that could be exploited by attackers to upload SVG files containing XSS code in the administration panel to obtain user cookies and construct phishing attacks.

EPSS

0.001

Percentile

41.3%