VDB
Sign up
LOW

GHSA-mj32-r678-7mvp

Craft Commerce has stored XSS in Craft Commerce Order Details Slideout

Quick fix

GHSA-mj32-r678-7mvp — craftcms/commerce: upgrade to the fixed version with the command below.

composer require craftcms/commerce:^4.10.2

Details

## Summary A Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the **Shipping Method Name**, **Order Reference**, or **Site Name**. When a user opens the order details slideout via a double-click on the order index page, the injected payload executes.

## Reproduction Steps 1. Navigate to **Commerce** -> **Store Management** -> **Shipping Methods**. 1. Click "New Shipping Method". 1. In the **Name** field, enter the following XSS payload: ```html <img src=x onerror=alert('XSS_Shipping')> ``` 1. Save the Shipping Method. 1. Place a new order or edit an existing order. 1. Set the order's **Shipping Method** to the one created in the previous steps. 1. Navigate to the **Orders** index page (`/admin/commerce/orders`). 1. Double-click the target order to open the details slideout. 1. **Result**: The XSS payload executes.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/commerce
Introduced in: 4.0.0Fixed in: 4.10.2
Fixcomposer require craftcms/commerce:^4.10.2
Packagist/craftcms/commerce
Introduced in: 5.0.0Fixed in: 5.5.3
Fixcomposer require craftcms/commerce:^5.5.3

References