OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Moderate severity
GitHub Reviewed
Published
Jul 14, 2022
in
oroinc/orocommerce
•
Updated Jan 12, 2023
Description
Published to the GitHub Advisory Database
Jul 15, 2022
Reviewed
Jul 15, 2022
Last updated
Jan 12, 2023
Impact
Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager
Relates to
Patch
Update GrapeJS dependency to >=v0.19.5
References