{"id":"GHSA-2jc6-3fhj-8q84","summary":"OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item","details":"### Impact\n\nThe JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product.\nAn attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it.\n","aliases":["CVE-2022-35950"],"modified":"2026-08-24T00:35:32.112055587Z","published":"2023-10-10T21:10:28Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-10-10T21:10:28Z","nvd_published_at":"2023-10-09T14:15:10Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/oroinc/orocommerce/security/advisories/GHSA-2jc6-3fhj-8q84"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35950"},{"type":"PACKAGE","url":"https://github.com/oroinc/orocommerce"}],"affected":[{"package":{"name":"oro/commerce","ecosystem":"Packagist","purl":"pkg:composer/oro/commerce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"last_affected":"4.1.13"}]}],"versions":["4.1.0","4.1.1","4.1.1-rc","4.1.1-rc2","4.1.10","4.1.11","4.1.12","4.1.13","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-2jc6-3fhj-8q84/GHSA-2jc6-3fhj-8q84.json"}},{"package":{"name":"oro/commerce","ecosystem":"Packagist","purl":"pkg:composer/oro/commerce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"last_affected":"4.2.10"}]}],"versions":["4.2.0","4.2.1","4.2.10","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-2jc6-3fhj-8q84/GHSA-2jc6-3fhj-8q84.json"}},{"package":{"name":"oro/commerce","ecosystem":"Packagist","purl":"pkg:composer/oro/commerce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.11"}]}],"versions":["5.0.0","5.0.1","5.0.10","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-2jc6-3fhj-8q84/GHSA-2jc6-3fhj-8q84.json"}},{"package":{"name":"oro/commerce","ecosystem":"Packagist","purl":"pkg:composer/oro/commerce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.1.1"}]}],"versions":["5.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-2jc6-3fhj-8q84/GHSA-2jc6-3fhj-8q84.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}