PT-2026-5747 · Pixel & Tonic · Craft Commerce

Mhe4Am

·

Publicado

2026-02-02

·

Atualizado

2026-02-03

·

CVE-2026-25487

CVSS v4.0

6.1

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Craft Commerce versions 4.0.0-RC1 through 4.10.0 Craft Commerce versions 5.0.0 through 5.5.1
Description Craft Commerce, an ecommerce platform for Craft CMS, contains a stored cross-site scripting (XSS) issue. The issue resides in the Tax Rates 'Name' field within the Store Management section, which does not properly sanitize input before displaying it in the admin panel. This allows attackers to inject malicious JavaScript code that executes in an administrator's browser. An attacker could potentially escalate privileges to administrator by exploiting this issue, especially if an elevated session exists. The attacker can also create a fake 'Session Expired' login modal overlay to steal administrator credentials. The vulnerable field is located at /admin/commerce/store-management/primary/taxrates. The Name field is the vulnerable parameter.
Recommendations Craft Commerce versions 4.0.0-RC1 through 4.10.0: Upgrade to version 4.10.1 or later. Craft Commerce versions 5.0.0 through 5.5.1: Upgrade to version 5.5.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25487
GHSA-WQC5-485V-3HQH

Produtos afetados

Craft Commerce