PT-2022-20477 · Unknown · Orocommerce

Rgrebenchuk

·

Published

2022-10-18

·

Updated

2022-10-20

·

CVE-2022-31037

CVSS v3.1

6.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OroCommerce versions 4.1.0 through 4.1.17 OroCommerce versions 4.2.0 through 4.2.11 OroCommerce versions 5.0.0 through 5.0.3
Description The issue concerns Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit page. An attacker needs permission to create or edit a shipping rule to exploit this.
Recommendations For versions 4.1.0 through 4.1.17, update to a version newer than 5.0.3, specifically to version 5.0.6 or later. For versions 4.2.0 through 4.2.11, update to a version newer than 5.0.3, specifically to version 5.0.6 or later. For versions 5.0.0 through 5.0.3, update to version 5.0.6 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31037
GHSA-4VF4-955G-VXP2

Affected Products

Orocommerce