Impact
Loaded Commerce 6.6 contains a client‑side template injection flaw that allows unauthenticated attackers to execute arbitrary code in the victim’s browser context by manipulating the search parameter. This weakness (CWE‑78) enables malicious script payloads to run when a user visits a crafted URL, potentially leading to phishing, data theft, or credential compromise in the victim’s environment. Based on the description, it is inferred that the attack vector is client‑side and relies solely on manipulating the search parameter in the URL.
Affected Systems
The flaw affects the Loaded Commerce product, specifically version 6.6. Users running this version are exposed to the risk and should verify their installation and consider upgrading.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is below 1%, suggesting the likelihood of exploitation is low at present. The vulnerability is not catalogued in CISA’s KEV list. Attack access is unauthenticated, relying on a client‑side input vector – the search field – to deliver malicious template payloads that execute in the victim’s browser rather than on the server. Based on the description, it is inferred that the attacker only needs to craft a malicious URL and entice a victim to visit it; no credentials are needed. No evidence of zero‑day exploitation exists, but exploit code is available in public exploit databases.
OpenCVE Enrichment