Impact
A stored Cross‑Site Scripting (XSS) flaw in Adobe Commerce allows a low‑privileged user to inject malicious JavaScript into form fields that are later displayed to other users. When a victim visits the affected page, the injected script runs in their browser with the site’s privileges, potentially enabling data theft, session hijacking, or further malicious actions. The vulnerability is classified as CWE‑79 and escalates the attacker’s privilege scope, making the impact more severe than a simple script injection.
Affected Systems
Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source are all susceptible to this flaw. The affected software does not have version information in the public advisory, so any deployment of these products prior to the latest patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% signifies a very low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers would need the ability to submit content to a vulnerable form, so the attack vector is likely local or requires user interaction. Even though exploitation likelihood is low, the potential for cross‑domain compromise makes it a notable risk for exposed sites.
OpenCVE Enrichment