Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vf4-955g-vxp2

Опубликовано: 18 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.9

Описание

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

Impact

Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.

Пакеты

Наименование

oro/commerce

composer
Затронутые версииВерсия исправления

>= 4.1.0, < 5.0.6

5.0.6

EPSS

Процентиль: 50%
0.00269
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.9
nvd
больше 3 лет назад

OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit page. The attacker needs permission to create or edit a shipping rule. This issue has been patched in version 5.0.6. There are no known workarounds.

EPSS

Процентиль: 50%
0.00269
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-79