Impact
Adobe Commerce is affected by a stored cross‑site scripting (XSS) vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. The injected script is stored and executed in victims’ browsers when they view the affected page, potentially enabling the attacker to gain elevated access or take control of the victim’s account or session. The vulnerability’s scope is changed.
Affected Systems
The affected systems are Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. No specific version information is included in the data.
Risk and Exploitability
CVSS 8.7 indicates a high severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves submitting malicious script payloads through vulnerable form fields; with low privileges the attacker can persistently store the payload so that any user who later views the affected page will execute the malicious code in their browser, which can lead to session hijacking or elevated account privileges. Because the scope is changed, the impact could extend beyond the initial target and affect broader parts of the application.
OpenCVE Enrichment