Impact
Adobe Commerce and related products contain a stored Cross-site Scripting flaw that allows an attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits the page containing the injected code, the script executes in the victim’s browser, which can lead to account takeover or session hijacking. The vulnerability is marked as a scope‑changing flaw, indicating that compromised clients may affect the entire affected system.
Affected Systems
The affected vendors and products are Adobe Commerce, Adobe Commerce B2B and Magento Open Source. No specific product versions are listed, so all currently deployed releases are considered affected until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 9.3 places the flaw in the high to critical range. EPSS data is not available and the issue is not listed in CISA’s KEV catalog, but the stored nature of the flaw and its ability to alter the session state mean that the risk of exploitation is tangible. The likely attack vector is a web‐based form submission; an attacker does not need privileged access to the server, only the ability to submit data that is stored and later rendered to other users’ browsers.
OpenCVE Enrichment