Due to insufficient class name validation in GrapeJS library it's possible to add executable JS code in class name through Selector Manager
Update GrapeJS dependency to >=v0.19.5
| Software | From | Fixed in |
|---|---|---|
oro / commerce
|
5.0 | 5.0.4 |