MEDIUM6.9
GHSA-6f85-3f8q-qc94
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Quick fix
GHSA-6f85-3f8q-qc94 — oro/commerce: upgrade to the fixed version with the command below.
composer require oro/commerce:^5.0.4Details
# Impact Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager
# Relates to - [https://github.com/artf/grapesjs/issues/4411](https://github.com/artf/grapesjs/issues/4411)
# Patch Update GrapeJS dependency to >=[v0.19.5](https://github.com/artf/grapesjs/releases/tag/v0.19.5)
Are you affected?
Enter the version of the package you're using.