Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6f85-3f8q-qc94: OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor

Impact

Due to insufficient class name validation in GrapeJS library it’s possible to add executable JS code in class name through Selector Manager

Relates to

Patch

Update GrapeJS dependency to >=v0.19.5

ghsa
#xss#js#git

OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor

Moderate severity GitHub Reviewed Published Jul 15, 2022 in oroinc/orocommerce • Updated Jul 15, 2022

ghsa: Latest News

GHSA-76mw-6p95-x9x5: pac4j-core affected by a Java deserialization vulnerability