Executive brief
Cradle eCommerce is a platform used for managing online stores and web projects. A security flaw in its demo version allows attackers to inject malicious scripts into the website's pages. If a user clicks a specially crafted link, an attacker could steal session information, perform actions on behalf of the user, or redirect them to malicious sites.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Cradle eCommerce demo platform due to improper neutralization of user-controlled input. The vulnerability is located in the '/collection/' endpoint, where input is insecurely reflected in the HTML output. An unauthenticated remote attacker can exploit this by tricking a user into visiting a malicious URL, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. The vendor has reportedly addressed the issue in the latest version of the platform.
Affected products
- Cradle CMS Cradle eCommerce demo latest demo version
Timeline
- 2026-05-08: disclosed: Initial disclosure by INCIBE-CERT
- 2026-05-11: advisory: NVD publication date