漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OroCommerce vulnerable to Cross-site Scripting via Shipping rule editing page
Vulnerability Description
OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit page. The attacker needs permission to create or edit a shipping rule. This issue has been patched in version 5.0.6. There are no known workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
OroCommerce 跨站脚本漏洞
Vulnerability Description
OroCommerce是Oro开源的一个开源的企业对企业商务应用程序。 OroCommerce 4.1.0 到4.1.17版本、4.2.0 到 4.2.11、以及 5.0.0 到 5.0.3版本存在跨站脚本 (XSS)漏洞,该漏洞源于易受运输规则编辑页面的 UPS 附加费字段中的跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A