PT-2024-36730 · Optimizely · Optimizely Configured Commerce

Published

2024-12-18

·

Updated

2025-06-05

·

CVE-2024-56173

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Optimizely Configured Commerce versions prior to 5.2.2408
Description The issue allows malicious payloads to be stored and subsequently executed in users' browsers under specific conditions. This is a result of XSS from JavaScript in an SVG document. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 5.2.2408, update to version 5.2.2408 or later to resolve the issue. As a temporary workaround, consider restricting the use of JavaScript in SVG documents to minimize the risk of exploitation. Avoid using SVG documents that contain JavaScript until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56173

Affected Products

Optimizely Configured Commerce