PT-2024-40404 · Thelia · Thelia

Published

2024-05-30

·

Updated

2024-05-30

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Thelia versions 2.1.0 through 2.1.1
Description The BackOffice of Thelia has a cross-site scripting issue in the error.html template.
Recommendations For versions 2.1.0 and 2.1.1, update to version 2.1.2 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

GHSA-PP7V-WXX9-HM6R

Affected Products

Thelia