MEDIUM6.9
GHSA-4vf4-955g-vxp2
OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration
Quick fix
GHSA-4vf4-955g-vxp2 — oro/commerce: upgrade to the fixed version with the command below.
composer require oro/commerce:^5.0.6Details
### Impact Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.
Are you affected?
Enter the version of the package you're using.