Medium severity6.9NVD Advisory· Published Oct 9, 2023· Updated Jun 17, 2026
CVE-2022-35950
CVE-2022-35950
Description
OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through 4.2.10, 5.0.0 prior to 5.0.11, and 5.1.0 prior to 5.1.1, the JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Versions 5.0.11 and 5.1.1 contain a fix for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oro/commercePackagist | >= 4.1.0, <= 4.1.13 | — |
oro/commercePackagist | >= 4.2.0, <= 4.2.10 | — |
oro/commercePackagist | >= 5.0.0, < 5.0.11 | 5.0.11 |
oro/commercePackagist | >= 5.1.0, < 5.1.1 | 5.1.1 |
Affected products
10>= 4.1.0, <= 4.1.13+ 8 more
- (no CPE)range: >= 4.1.0, <= 4.1.13
- cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*range: >=4.1.0,<=4.1.13
- cpe:2.3:a:oroinc:orocommerce:5.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:oroinc:orocommerce:5.1.0:rc2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-2jc6-3fhj-8q84ghsaADVISORY
- github.com/oroinc/orocommerce/security/advisories/GHSA-2jc6-3fhj-8q84nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-35950ghsaADVISORY
News mentions
0No linked articles in our index yet.