Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS00dmY0LTk1NWctdnhwMs4AAvap
OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration
Impact
Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.
Permalink: https://github.com/advisories/GHSA-4vf4-955g-vxp2JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dmY0LTk1NWctdnhwMs4AAvap
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 11 months ago
Updated: 8 months ago
CVSS Score: 6.9
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Identifiers: GHSA-4vf4-955g-vxp2, CVE-2022-31037
References:
- https://github.com/oroinc/orocommerce/security/advisories/GHSA-4vf4-955g-vxp2
- https://nvd.nist.gov/vuln/detail/CVE-2022-31037
- https://github.com/advisories/GHSA-4vf4-955g-vxp2
Affected Packages
packagist:oro/commerce
Versions: >= 4.1.0, < 5.0.6Fixed in: 5.0.6