VDB
Sign up
MEDIUM6.9

GHSA-6f85-3f8q-qc94

OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor

Quick fix

GHSA-6f85-3f8q-qc94 — oro/commerce: upgrade to the fixed version with the command below.

composer require oro/commerce:^5.0.4

Details

# Impact Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager

# Relates to - [https://github.com/artf/grapesjs/issues/4411](https://github.com/artf/grapesjs/issues/4411)

# Patch Update GrapeJS dependency to >=[v0.19.5](https://github.com/artf/grapesjs/releases/tag/v0.19.5)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oro/commerce
Introduced in: 5.0Fixed in: 5.0.4
Fixcomposer require oro/commerce:^5.0.4

References