Executive brief
Cradle eCommerce is a platform used for managing online stores and web projects. A security flaw in its product display pages allows attackers to inject malicious scripts into the website. If a user clicks a specially crafted link, an attacker could execute code in the user's browser, potentially leading to the theft of session cookies or unauthorized actions on the user's behalf.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Cradle eCommerce demo platform. The issue stems from improper neutralization of user-controlled input before it is reflected in the HTML output at the '/product/' endpoint. An unauthenticated remote attacker can exploit this by tricking a user into visiting a malicious URL containing a crafted payload. Successful exploitation allows the execution of arbitrary JavaScript within the context of the victim's browser session, which can be used to hijack sessions or perform actions as the user. The vendor has reportedly addressed the issue in the latest version of the platform.
Affected products
- Cradle CMS Cradle eCommerce demo Latest demo version (as of May 2026)
Timeline
- 2026-05-08: advisory: INCIBE-CERT published the initial advisory.
- 2026-05-11: disclosed: CVE-2026-3320 published to the NVD.