MEDIUM6.9
GHSA-rrgw-3hg3-9x8c
XSS vulnerability in translations
Quick fix
GHSA-rrgw-3hg3-9x8c — oro/platform: upgrade to the fixed version with the command below.
composer require oro/platform:^3.1.29Details
### Summary
An attacker with admin privileges and access to Translations management functionality may add JS payload to translation values via: - Translation management UI. - Translations downloaded via the Crowdin service may also contain JS strings used for XSS attacks, for a successful attack poisoned translation should be enabled, downloaded, and installed. - Translations uploaded via Upload translation file on the All Languages grid
### Workarounds
There are no workarounds that address this vulnerability.
Are you affected?
Enter the version of the package you're using.