Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| sylius/sylius(Packagist) | 1.12.0-alpha.1 | 1.12.16 | N/A |
| sylius/sylius(Packagist) | 1.13.0-alpha.1 | 1.13.1 | N/A |
CVSS Metrics