Junglewise Threat Intelligence

CVE-2023-46494: EverShop cross-site scripting in ProductGrid

CVE-2023-46494 · Severity: low · CVSS 3.1 · Published 2023-12-08

Technologies: @evershop/evershop (npm), EverShop. Vendors: npm, EverShop.

Executive brief

EverShop is a popular open-source e-commerce platform distributed via npm. A cross-site scripting (XSS) vulnerability in the ProductGrid admin component allows attackers to inject malicious scripts that could expose sensitive information or compromise administrator sessions through crafted requests. This affects all versions before 1.0.0-rc.5.

Technical details

A cross-site scripting (CWE-79) vulnerability exists in the ProductGrid function within admin/productGrid/Grid.jsx in EverShop npm package versions before 1.0.0-rc.5. The vulnerability is reachable over the network and requires user interaction (UI:R) but no authentication. An attacker can craft a malicious request to inject arbitrary JavaScript into the admin interface, potentially leading to session hijacking, credential theft, or unauthorized actions in the admin panel. The vulnerability was patched in version 1.0.0-rc.5 as indicated by the merged pull request #244.

Affected products

  • EverShop EverShop before 1.0.0-rc.5

Timeline

  • 2023-12-08: disclosed
  • 2023-04-27: patched: Patch merged in PR #244; fix available in version 1.0.0-rc.5

References

Related threats