VDB
Sign up
MEDIUM6.9

GHSA-4vf4-955g-vxp2

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

Quick fix

GHSA-4vf4-955g-vxp2 — oro/commerce: upgrade to the fixed version with the command below.

composer require oro/commerce:^5.0.6

Details

### Impact Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oro/commerce
Introduced in: 4.1.0Fixed in: 5.0.6
Fixcomposer require oro/commerce:^5.0.6

References