QID 996763
Date Published: 2024-01-23
QID 996763: PHP (Composer) Security Update for woocommerce/woocommerce (GHSA-mp46-7x6q-f28m)
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mp46-7x6q-f28m for updates and patch information.
Vendor References
- GHSA-mp46-7x6q-f28m -
github.com/advisories/GHSA-mp46-7x6q-f28m
CVEs related to QID 996763
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mp46-7x6q-f28m | woocommerce/woocommerce |
|