VDB
Sign up
MEDIUM4.8

GHSA-2jc6-3fhj-8q84

OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item

Quick fix

GHSA-2jc6-3fhj-8q84 — oro/commerce: upgrade to the fixed version with the command below.

composer require oro/commerce:^5.0.11

Details

### Impact

The JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oro/commerce
Introduced in: 4.1.0

No fixed version published yet for oro/commerce (composer). Pin to a known-safe version or switch to an alternative.

Packagist/oro/commerce
Introduced in: 4.2.0

No fixed version published yet for oro/commerce (composer). Pin to a known-safe version or switch to an alternative.

Packagist/oro/commerce
Introduced in: 5.0.0Fixed in: 5.0.11
Fixcomposer require oro/commerce:^5.0.11
Packagist/oro/commerce
Introduced in: 5.1.0Fixed in: 5.1.1
Fixcomposer require oro/commerce:^5.1.1

References