PT-2026-46081 · Packagist · Drupal Commerce
Publicado
2026-06-03
·
Atualizado
2026-06-03
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).
This vulnerability is mitigated by the fact that it only affects installations with Checkout (
commerce checkout) enabled, and the "Comments" checkout pane (id: customer comments) is explicitly used, which is disabled by default. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal Commerce