{"id":"GHSA-6f85-3f8q-qc94","aliases":[],"url":"https://o3.security/vulnerability/GHSA-6f85-3f8q-qc94","summary":"OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor","details":"# Impact\nDue to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager\n\n# Relates to\n - [https://github.com/artf/grapesjs/issues/4411](https://github.com/artf/grapesjs/issues/4411)\n\n# Patch\nUpdate GrapeJS dependency to >=[v0.19.5](https://github.com/artf/grapesjs/releases/tag/v0.19.5)\n","published":"2022-07-15T19:25:06Z","modified":"2024-12-08T05:39:08.302350Z","cvss":{"score":6.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"oro/commerce","fixedVersion":"5.0.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/oroinc/orocommerce/security/advisories/GHSA-6f85-3f8q-qc94"},{"type":"WEB","url":"https://github.com/artf/grapesjs/issues/4411"},{"type":"PACKAGE","url":"https://github.com/oroinc/orocommerce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-08T05:39:08.302350Z"}}