PT-2026-94343 · Vendure · Vendure
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vendure versions prior to 3.6.5
Description
Stored cross-site scripting (XSS) exists in the admin dashboard due to unsafe HTML stripping in the
RichTextDescriptionCell component within packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx. The component attempts to remove markup by assigning an administrator-controlled description to a live element's innerHTML and then reading the textContent. This process allows active resource markup, such as <img src=x onerror=...>, to execute event handlers during the assignment before the text is read.A lower-privilege administrator can store malicious markup in the
description fields of the Products, Collections, Promotions, Payment Methods, or Shipping Methods lists. The script executes when another administrator views the affected row, potentially compromising their session and enabling cross-privilege or cross-channel administrative actions.Recommendations
Update to version 3.6.5.
As a temporary workaround, restrict write permissions for the
description field in the Products, Collections, Promotions, Payment Methods, and Shipping Methods lists to trusted administrators only.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vendure