GHSA-6f85-3f8q-qc94

Suggest an improvement
Source
https://github.com/advisories/GHSA-6f85-3f8q-qc94
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-6f85-3f8q-qc94/GHSA-6f85-3f8q-qc94.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6f85-3f8q-qc94
Published
2022-07-15T19:25:06Z
Modified
2024-12-08T05:39:08Z
Severity
  • 6.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
Summary
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Details

Impact

Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager

Relates to

Patch

Update GrapeJS dependency to >=v0.19.5

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-07-15T19:25:06Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / oro/commerce

Package

Name
oro/commerce
Purl
pkg:composer/oro/commerce

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0
Fixed
5.0.4

Affected versions

5.*
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-beta.1
5.0.0-beta.2
5.0.0-rc
5.0.0
5.0.1
5.0.2
5.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-6f85-3f8q-qc94/GHSA-6f85-3f8q-qc94.json"