GHSA-gm68-572p-q28r

    Dashboard / Vulnerabilities / GHSA-gm68-572p-q28r

    GHSA-gm68-572p-q28r

    Published: 6 Jul 2023Last Modified: 6 Jul 2023

    Summary: @vendure/admin-ui-plugin authenticated Cross-site Scripting vulnerability

    Details: ### Impact Vendure provides an authorization system with different levels of privileges. For example, an administrator cannot create another administrator. In the admin UI, there are a couple of places with description inputs, such as inventory/collection catalog, shipping methods, promotions, and more. While the WYSIWYG editor allows limited customization, altering the request data (not in the ui) saves and returns arbitrary HTML with no sanitization. Causing an XSS when viewing the page. The impact of this XSS is privilege escalation. A user that can write any type of description can trigger the attack. Then any other user that visits the vulnerable page is prone to arbitrary Javascript code execution, giving the attacker ability to execute actions on behalf of this user. ### Patches in progress ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ ### References _Are there any links users can visit to find out more?_

    Affected packages

    Package

    Name: @vendure/admin-ui-plugin

    Purl: pkg:npm/%40vendure/admin-ui-plugin

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.0.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-gm68-572p-q28r | CVE-DB