PT-2026-46081 · Packagist · Drupal Commerce

Publicado

2026-06-03

·

Atualizado

2026-06-03

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).
This vulnerability is mitigated by the fact that it only affects installations with Checkout (commerce checkout) enabled, and the "Comments" checkout pane (id: customer comments) is explicitly used, which is disabled by default.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

DRUPAL-CONTRIB-2026-041

Produtos afetados

Drupal Commerce