GHSA-rrgw-3hg3-9x8c
Dashboard / Vulnerabilities / GHSA-rrgw-3hg3-9x8c
GHSA-rrgw-3hg3-9x8c
Published: 12 Jan 2022Last Modified: 4 Dec 2024
Summary: XSS vulnerability in translations
Details: ### Summary An attacker with admin privileges and access to Translations management functionality may add JS payload to translation values via: - Translation management UI. - Translations downloaded via the Crowdin service may also contain JS strings used for XSS attacks, for a successful attack poisoned translation should be enabled, downloaded, and installed. - Translations uploaded via Upload translation file on the All Languages grid ### Workarounds There are no workarounds that address this vulnerability.
Affected packages
Package
Name: oro/platform
Purl: pkg:composer/oro/platform
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 3.1.0
Fixed -3.1.29
Affected versions
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.20
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
