Impact
Adobe Commerce is vulnerable to a stored cross‑site scripting flaw that allows an attacker to embed malicious JavaScript into certain form fields. When a victim visits the affected page, the browser executes the injected script, which can hijack the user's session, exfiltrate credentials, or perform actions with the victim’s privileges. The vulnerability is classified as CWE-79 and is rated with a CVSS score of 9.3, indicating high severity. The impact is a change in scope; it fails to affect the attacker’s own session but grants the attacker unauthorized control over the victim’s account.
Affected Systems
Advised systems include Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific product versions are listed, so all current or older releases that have not applied the Adobe advisory are potentially affected.
Risk and Exploitability
The high CVSS score and lack of mitigation suggest this flaw is exploitable in typical web‑application contexts where users can submit data to the vulnerable fields. The exploit path requires the attacker to supply malicious input that is stored and later rendered as part of a page. Since the EPSS score is unavailable and the vulnerability is not in CISA’s KEV catalog, there is no public evidence of weaponized exploits at this time, but the inherent nature of stored XSS makes it a priority for rapid patching.
OpenCVE Enrichment