Описание
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Impact
Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager
Relates to
Patch
Update GrapeJS dependency to >=v0.19.5
Пакеты
Наименование
oro/commerce
composer
Затронутые версииВерсия исправления
>= 5.0, < 5.0.4
5.0.4
6.9 Medium
CVSS3
Дефекты
CWE-79
6.9 Medium
CVSS3
Дефекты
CWE-79