Impact
Adobe Commerce is vulnerable to a stored XSS flaw that allows a low‑privileged attacker to inject malicious scripts into form fields. When a victim visits the page containing the compromised field, the script runs in their browser and may elevate the attacker’s access or take control of the victim’s account. The impact is chiefly confidentiality and integrity of the victim session, and it alters the scope of the affected system.
Affected Systems
Affected products include Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version information was provided, so all current installations of these products require assessment.
Risk and Exploitability
The CVSS v3.1 score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV, and the exploit requires conditions beyond the attacker’s direct control. The likely attack vector is via a low‑privileged authenticated user submitting data to the vulnerable form, and this inference is noted where explicit information is absent.
OpenCVE Enrichment