PT-2026-50382 · Simplcommerce+1 · Simplcommerce
CVSS v4.0
6.2
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SimplCommerce versions prior to commit 6142d3b5
Description
Stored cross-site scripting (XSS) exists in the 'NewsItemApiController' endpoint. An authenticated administrator can execute arbitrary JavaScript through the
ShortContent and FullContent fields. This occurs because the input is stored without HTML sanitization and is subsequently rendered unencoded using the @Html.Raw() function.Recommendations
Update SimplCommerce to commit 6142d3b5 or a later version.
As a temporary mitigation, restrict administrative access to the news item management features.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplcommerce