GHSA-mj32-r678-7mvp
Craft Commerce has stored XSS in Craft Commerce Order Details Slideout
Quick fix
GHSA-mj32-r678-7mvp — craftcms/commerce: upgrade to the fixed version with the command below.
composer require craftcms/commerce:^4.10.2Details
## Summary A Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the **Shipping Method Name**, **Order Reference**, or **Site Name**. When a user opens the order details slideout via a double-click on the order index page, the injected payload executes.
## Reproduction Steps 1. Navigate to **Commerce** -> **Store Management** -> **Shipping Methods**. 1. Click "New Shipping Method". 1. In the **Name** field, enter the following XSS payload: ```html <img src=x onerror=alert('XSS_Shipping')> ``` 1. Save the Shipping Method. 1. Place a new order or edit an existing order. 1. Set the order's **Shipping Method** to the one created in the previous steps. 1. Navigate to the **Orders** index page (`/admin/commerce/orders`). 1. Double-click the target order to open the details slideout. 1. **Result**: The XSS payload executes.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0Fixed in: 4.10.2composer require craftcms/commerce:^4.10.25.0.0Fixed in: 5.5.3composer require craftcms/commerce:^5.5.3