{"id":"GHSA-4vf4-955g-vxp2","summary":"OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration","details":"### Impact\nShipping rule edit page is vulnerable to cross site scripting (XSS) payload added to UPS Surcharge field. The attacker should have permission to create or edit a shipping rule.","aliases":["CVE-2022-31037"],"modified":"2023-11-08T04:09:23.576414Z","published":"2022-10-18T19:52:25Z","database_specific":{"cwe_ids":["CWE-79"],"github_reviewed_at":"2022-10-18T19:52:25Z","github_reviewed":true,"nvd_published_at":"2022-10-18T10:15:00Z","severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/oroinc/orocommerce/security/advisories/GHSA-4vf4-955g-vxp2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31037"},{"type":"PACKAGE","url":"https://github.com/oroinc/orocommerce"}],"affected":[{"package":{"name":"oro/commerce","ecosystem":"Packagist","purl":"pkg:composer/oro/commerce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"5.0.6"}]}],"versions":["4.1.0","4.1.1","4.1.1-rc","4.1.1-rc2","4.1.10","4.1.11","4.1.12","4.1.13","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9","4.2.0","4.2.0-alpha","4.2.0-alpha.1","4.2.0-alpha.2","4.2.0-alpha.3","4.2.0-beta","4.2.0-rc","4.2.1","4.2.10","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9","5.0.0","5.0.0-alpha.1","5.0.0-alpha.2","5.0.0-beta.1","5.0.0-beta.2","5.0.0-rc","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-4vf4-955g-vxp2/GHSA-4vf4-955g-vxp2.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"}]}