Impact
Vendure’s dashboard component RichTextDescriptionCell strips markup by temporarily inserting an administrator‑controlled description into a live element’s innerHTML and then reading its textContent. During the innerHTML assignment, any event handler in the injected markup can execute, allowing a malicious administrator to embed scripts that run when another administrator later views the affected row. This stored cross‑site scripting attack can compromise the viewing administrator’s session cookie and permit cross‑privilege or cross‑channel administrative actions.
Affected Systems
Any instance of vendurehq:vendure with a version earlier than 3.6.5 is affected. The vulnerability can be triggered in the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, where lower‑privilege administrators can store malicious markup in entity descriptions.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, but the lack of a listed KEV suggests no confirmed exploits yet. An attacker must first create or edit an entity description using a lower‑privilege administrator account, then rely on a higher‑privilege administrator to trigger the stored script by viewing the list. Once triggered, the script can hijack the session, enabling privileged actions or further exploitation.
OpenCVE Enrichment
Github GHSA