{"id":"GHSA-rrgw-3hg3-9x8c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rrgw-3hg3-9x8c","summary":"XSS vulnerability in translations","details":"### Summary\n\nAn attacker with admin privileges and access to Translations management functionality may add JS payload to translation values via: \n - Translation management UI.\n - Translations downloaded via the Crowdin service may also contain JS strings used for XSS attacks, for a successful attack poisoned translation should be enabled, downloaded, and installed.\n - Translations uploaded via Upload translation file on the All Languages grid\n\n### Workarounds\n\nThere are no workarounds that address this vulnerability.","published":"2022-01-12T21:49:49Z","modified":"2024-12-04T05:26:33.750101Z","cvss":{"score":6.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"oro/platform","fixedVersion":"3.1.29"},{"ecosystem":"Packagist","name":"oro/platform","fixedVersion":"4.1.17"},{"ecosystem":"Packagist","name":"oro/platform","fixedVersion":"4.2.8"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/oroinc/platform-er/security/advisories/GHSA-rrgw-3hg3-9x8c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:26:33.750101Z"}}