Junglewise Threat Intelligence

CVE-2023-46499: EverShop cross-site scripting in Admin Panel

CVE-2023-46499 · Severity: low · CVSS 3.1 · Published 2023-12-08

Technologies: EverShop, @evershop/evershop (npm). Vendors: EverShop, npm.

Executive brief

EverShop is an open-source e-commerce platform npm package used to build online stores. An attacker can inject malicious scripts into the Admin Panel that execute in the browsers of administrators viewing crafted content, potentially allowing them to steal sensitive information or perform unauthorized actions on behalf of legitimate admin users.

Technical details

This is a Stored or Reflected Cross-Site Scripting (XSS) vulnerability (CWE-79) in the EverShop npm package affecting versions before 1.0.0-rc.5. The vulnerability allows an unauthenticated remote attacker to inject malicious scripts via a crafted payload targeting the Admin Panel. The attack requires user interaction (an admin must view or interact with the malicious content). Successful exploitation enables an attacker to access sensitive information, modify admin content, or hijack admin sessions. The vulnerability was patched in version 1.0.0-rc.5.

Affected products

  • EverShop evershop before 1.0.0-rc.5

Timeline

  • 2023-12-08: disclosed
  • 2023-12-08: patched: Fixed in version 1.0.0-rc.5

References

Related threats