QID 995542
Date Published: 2023-10-11
QID 995542: PHP (Composer) Security Update for oro/commerce (GHSA-2jc6-3fhj-8q84)
The JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-2jc6-3fhj-8q84 for updates and patch information.
Vendor References
- GHSA-2jc6-3fhj-8q84 -
github.com/advisories/GHSA-2jc6-3fhj-8q84
CVEs related to QID 995542
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2jc6-3fhj-8q84 | oro/commerce |
|