oro/commerce Security Advisories for 4.1.1-rc (2)
-
[MEDIUM] OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
PKSA-6m1x-w3qg-gqvr CVE-2022-35950 GHSA-2jc6-3fhj-8q84
Affected version: >=5.1.0,<5.1.1|>=5.0.0,<5.0.11|>=4.2.0,<=4.2.10|>=4.1.0,<=4.1.13
Reported by:
GitHub -
[MEDIUM] OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration
PKSA-rtnt-5225-nzch CVE-2022-31037 GHSA-4vf4-955g-vxp2
Affected version: >=4.1.0,<5.0.6
Reported by:
GitHub