« Volver al listado

CVE-2022-31037

Estado: ModificadaMedia (5.4)—

OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit page. The attacker needs permission to create or edit a shipping rule. This issue has been patched in version 5.0.6. There are no known workarounds.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-31037",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-31037",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-23T13:56:12.466489Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "oroinc",
          "product": "orocommerce",
          "versions": [
            {
              "status": "affected",
              "version": ">= 4.1.0, <= 4.1.17"
            },
            {
              "status": "affected",
              "version": ">= 4.2.0, <= 4.2.11 "
            },
            {
              "status": "affected",
              "version": ">= 5.0.0, <= 5.0.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-18T10:15:10.383",
  "references": [
    {
      "url": "https://github.com/oroinc/orocommerce/security/advisories/GHSA-4vf4-955g-vxp2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/oroinc/orocommerce/security/advisories/GHSA-4vf4-955g-vxp2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OroCommerce is an open-source Business to Business Commerce application. Versions between 4.1.0 and 4.1.17 inclusive, 4.2.0 and 4.2.11 inclusive, and between 5.0.0 and 5.0.3 inclusive, are vulnerable to Cross-site Scripting in the UPS Surcharge field of the Shipping rule edit page. The attacker needs permission to create or edit a shipping rule. This issue has been patched in version 5.0.6. There are no known workarounds."
    },
    {
      "lang": "es",
      "value": "OroCommerce es una aplicación de comercio entre empresas de código abierto. Las versiones entre 4.1.0 y 4.1.17 incluyéndola, 4.2.0 y 4.2.11 incluyéndola, y entre 5.0.0 y 5.0.3 incluyéndola, son vulnerables a un ataque de tipo Cross-site Scripting en el campo UPS Surcharge de la página de edición de reglas de envío. El atacante necesita permiso para crear o editar una regla de envío. Este problema ha sido corregido en versión 5.0.6. No se presentan mitigaciones conocidas"
    }
  ],
  "lastModified": "2026-06-17T04:44:39.657",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B2E64AD-7486-4B83-9F78-C9CF58F13901",
              "versionEndIncluding": "4.1.17",
              "versionStartIncluding": "4.1.0"
            },
            {
              "criteria": "cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F0DBDA7-13AC-42A1-B74A-B5AAFD7AA299",
              "versionEndIncluding": "4.2.11",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7100B052-D2C8-4D9C-A055-CCA84A7D5432",
              "versionEndIncluding": "5.0.3",
              "versionStartIncluding": "5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}