Executive brief
Adobe Commerce, a widely-used e-commerce platform, contains a stored cross-site scripting (XSS) vulnerability in form fields that allows low-privileged attackers to inject malicious scripts. When legitimate users browse pages with the injected content, the attacker's JavaScript executes in their browsers, potentially enabling account takeover, session hijacking, or unauthorized administrative actions. The impact depends on specific deployment conditions and user interactions.
Technical details
The vulnerability is a stored (persistent) cross-site scripting flaw in form field handling within Adobe Commerce. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; this payload is stored in the application and executed in the browsers of any users who view the affected page. The attack vector is network-based and requires user interaction (a victim must browse the page), but does not require administrative privileges to inject the payload. An attacker can achieve account compromise, session hijacking, or privilege escalation depending on the victim's role. Patch availability status is unclear from the provided information.
Affected products
- Adobe Commerce
Timeline
- 2026-08-11: disclosed