GHSA-2jc6-3fhj-8q84
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
Quick fix
GHSA-2jc6-3fhj-8q84 — oro/commerce: upgrade to the fixed version with the command below.
composer require oro/commerce:^5.0.11Details
### Impact
The JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.1.0No fixed version published yet for oro/commerce (composer). Pin to a known-safe version or switch to an alternative.
4.2.0No fixed version published yet for oro/commerce (composer). Pin to a known-safe version or switch to an alternative.