Headline
GHSA-6f85-3f8q-qc94: OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Impact
Due to insufficient class name validation in GrapeJS library it’s possible to add executable JS code in class name through Selector Manager
Relates to
Patch
Update GrapeJS dependency to >=v0.19.5
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Moderate severity GitHub Reviewed Published Jul 15, 2022 in oroinc/orocommerce • Updated Jul 15, 2022