PT-2025-23496 · Unknown · Ce Phoenix

Adityaax

·

Published

2025-06-02

·

Updated

2025-06-02

·

CVE-2025-47289

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CE Phoenix versions 1.0.9.9 through 1.1.0.2
Description A stored cross-site scripting (XSS) issue was found in CE Phoenix, where an attacker can inject malicious JavaScript into the testimonial description field. If the shop owner approves the testimonial, the script executes in the context of any user visiting the testimonial page. The session cookies can be exfiltrated by the attacker because they are not marked with the HttpOnly flag, potentially leading to account takeover.
Recommendations For versions 1.0.9.9 through 1.1.0.2, update to version 1.1.0.3 to fix the issue. As a temporary workaround, consider restricting access to the testimonial description field until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-10516
CVE-2025-47289
GHSA-98QQ-M8QJ-VVGJ

Affected Products

Ce Phoenix