Description
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Tax Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel. This issue has been patched in versions 4.10.1 and 5.5.2.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
>= 5.0.0, < 5.5.2
References
github.com/...mmerce/security/advisories/GHSA-p6w8-q63m-72c8
github.com/...ommit/fa273330807807d05b564d37c88654cd772839ee
github.com/craftcms/commerce/releases/tag/4.10.1
github.com/craftcms/commerce/releases/tag/5.5.2