PT-2023-13453 · Unknown · Orocommerce

Khrysev

·

Publicado

2023-10-09

·

Atualizado

2023-10-12

·

CVE-2022-35950

CVSS v3.1

6.9

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OroCommerce versions 4.1.0 through 4.1.13 OroCommerce versions 4.2.0 through 4.2.10 OroCommerce versions 5.0.0 through 5.0.10 OroCommerce versions 5.1.0
Description The issue allows a JS payload added to the product name to be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker can edit a product in the admin area and force a user to add this product to the Shopping List and click add a note for it.
Recommendations For versions 4.1.0 through 4.1.13, update to version 5.0.11 or later. For versions 4.2.0 through 4.2.10, update to version 5.0.11 or later. For versions 5.0.0 through 5.0.10, update to version 5.0.11. For version 5.1.0, update to version 5.1.1.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-35950
GHSA-2JC6-3FHJ-8Q84

Produtos afetados

Orocommerce