Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS00dmY0LTk1NWctdnhwMs4AAvap

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

Impact

Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.

Permalink: https://github.com/advisories/GHSA-4vf4-955g-vxp2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dmY0LTk1NWctdnhwMs4AAvap
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 11 months ago
Updated: 8 months ago


CVSS Score: 6.9
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

Identifiers: GHSA-4vf4-955g-vxp2, CVE-2022-31037
References:

Affected Packages

packagist:oro/commerce
Versions: >= 4.1.0, < 5.0.6
Fixed in: 5.0.6