EIP-2026-114487
PRE-CVEXT:Commerce < 3.04 SP2.1 - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114487. PoCs published by Philipp Niedziela.
AI-analyzed exploit summary This is a technical writeup describing a stored XSS vulnerability in XT:Commerce < 3.04 SP2.1. The vulnerability allows an attacker to inject malicious JavaScript into the 'street' field during account creation, which executes when an administrator views the order in the backend.
Description
XT:Commerce < 3.04 SP2.1 - Cross-Site Scripting
Exploits (1)
This is a technical writeup describing a stored XSS vulnerability in XT:Commerce < 3.04 SP2.1. The vulnerability allows an attacker to inject malicious JavaScript into the 'street' field during account creation, which executes when an administrator views the order in the backend.