CVE-2022-31037

MEDIUM6.9EPSS 0.28%

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

Published: 10/18/2022Modified: 11/8/2023
Also known as:GHSA-4vf4-955g-vxp2

Description

### Impact Shipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.9CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N

References (3)