XSS Vulnerability in Sylius E-commerce Platform
CVE-2019-12186
4.8MEDIUM
What is CVE-2019-12186?
A vulnerability has been identified in Sylius products that lacks adequate input sanitization in various versions. This weakness allows an attacker, particularly an admin within the Sylius platform, to exploit the system by injecting malicious code into fields displayed in a grid. The malicious code can be executed when the object’s __toString() method returns the code, leading to potential unauthorized actions and data manipulation.