Impact
Ready eCommerce versions prior to 4.5.2 contain a stored cross‑site scripting flaw that is triggered by authenticated customers through the chat and support ticket messaging interfaces. The vulnerability results from unsanitized HTML rendering via the v-html directive in multiple Vue components, allowing an attacker to embed arbitrary JavaScript that executes in the browser of any shop owner or administrator who views the message. The primary consequence of this flaw is the theft of session cookies and the potential for full account takeover for the target user.
Affected Systems
The affected vendor is Razinsoft, whose Ready eCommerce product is impacted when deployed in any version earlier than 4.5.2. All installations using a pre‑4.5.2 release are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 5.1 positions this issue as medium severity, and the exploitation probability is not quantified by EPSS. The flaw requires the attacker to be a logged‑in customer and rely on a target administrator or shop owner viewing the injected message, which limits its reach but still poses a significant threat if successful. Since it is not listed in CISA KEV, no known active exploits have been reported yet, yet the potential for session hijacking warrants timely remediation.
OpenCVE Enrichment