Impact
Concrete CMS Community Store versions prior to 2.7.8 render customer‑supplied billing fields without escaping, enabling stored XSS. An unauthenticated attacker can upload a script payload into the billing name, email, or phone fields during checkout or admin order view. When a manager logs in, the malicious script executes in the manager’s browser, allowing the attacker to create rogue accounts or exfiltrate sensitive data. The weakness is a classic stored XSS object (CWE‑79).
Affected Systems
Entities running Concrete CMS Community Store before version 2.7.8 are affected. The vulnerability applies to all installations using the community_store package, specifically those versions older than 2.7.8.
Risk and Exploitability
The CVSS score of 8.6 flags this issue as a critical vulnerability. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can achieve it through an unauthenticated input vector, meaning any user with access to the checkout or order creation interfaces can submit a malicious payload. Because the payload is stored and later executed in a privileged context, the risk to integrity and confidentiality is high, and the exploitation likelihood can be considered significant given the high severity rating.
OpenCVE Enrichment