GHSA-gg96-8w9x-7rx9

Suggest an improvement
Source
https://github.com/advisories/GHSA-gg96-8w9x-7rx9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gg96-8w9x-7rx9/GHSA-gg96-8w9x-7rx9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gg96-8w9x-7rx9
Aliases
Published
2022-05-24T16:52:27Z
Modified
2024-02-16T08:14:47Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Magento 2 Community Edition Cross-site Scripting Vulnerability
Details

A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the product catalog to inject malicious javascript.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-08-01T23:01:21Z",
    "nvd_published_at":  "2019-08-02T22:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.18

Affected versions

2.*
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gg96-8w9x-7rx9/GHSA-gg96-8w9x-7rx9.json"

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2.0
Fixed
2.2.9

Affected versions

2.*
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gg96-8w9x-7rx9/GHSA-gg96-8w9x-7rx9.json"

Packagist / magento/community-edition

Package

Name
magento/community-edition
Purl
pkg:composer/magento/community-edition

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.2

Affected versions

2.*
2.3.0
2.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gg96-8w9x-7rx9/GHSA-gg96-8w9x-7rx9.json"