GHSA-w8gw-qm8p-j9j3

Suggest an improvement
Source
https://github.com/advisories/GHSA-w8gw-qm8p-j9j3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-w8gw-qm8p-j9j3/GHSA-w8gw-qm8p-j9j3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w8gw-qm8p-j9j3
Aliases
Published
2026-02-02T22:45:03Z
Modified
2026-02-22T23:26:11Z
Severity
  • 6.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Details

Summary

A stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the admin panel.


Proof of Concept

Requirments

  • General permissions:
    • Access the control panel
    • Access Craft Commerce
  • Craft Commerce permissions:
    • Manage store settings
    • Manage shipping
  • An active administrator elevated session

Steps to Reproduce

  1. Log in to the Admin Panel with the attacker account with the permissions mentioned above.
  2. Navigate to Commerce -> Store Management -> Shipping Categories (/admin/commerce/store-management/primary/shippingcategories).
  3. Create a new shipping category.
  4. In the Name field, enter the following payload:
<img src=x onerror="alert(document.domain)">
  1. Click Save & Go back to the previous page.
  2. Notice the alert proving JavaScript execution.

Privilege Escalation to Administrator:

  1. Do the same steps above, but replace the payload with a malicious one.
  2. The following payload elevates the attacker’s account to Admin if there’s already an elevated session, replace the <UserID> with your attacker id:
<img src=x onerror="fetch('/admin/users/<UserID>/permissions',{method:'POST',body:`CRAFT_CSRF_TOKEN=${Craft.csrfTokenValue}&userId=<UserID>&admin=1&action=users/save-permissions`,headers:{'content-type':'application/x-www-form-urlencoded'}})">
  1. In another browser, log in as an admin & go to the vulnerable page (shipping categories page).
  2. Go back to your attacker account & notice you are now an admin.

The privilege escalation requires an elevated session. In a real-world scenario, an attacker can automate the process by forcing a logout if the victim’s session is stale; upon re-authentication, the stored XSS payload executes within a fresh elevated session to complete the attack.

Or even easier (and smarter), an attacker (using the XSS) can create a fake 'Session Expired' login modal overlay. Since it’s on the trusted domain, administrators will likely enter their credentials, sending them directly to the attacker.

Resources:

https://github.com/craftcms/commerce/commit/fa273330807807d05b564d37c88654cd772839ee

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-02T22:45:03Z",
    "nvd_published_at":  "2026-02-03T19:16:26Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / craftcms/composer

Package

Name
craftcms/composer
Purl
pkg:composer/craftcms/composer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0-RC1
Fixed
5.5.2

Database specific

last_known_affected_version_range
"<= 5.5.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-w8gw-qm8p-j9j3/GHSA-w8gw-qm8p-j9j3.json"

Packagist / craftcms/composer

Package

Name
craftcms/composer
Purl
pkg:composer/craftcms/composer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0-RC1
Fixed
4.10.1

Database specific

last_known_affected_version_range
"<= 4.10.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-w8gw-qm8p-j9j3/GHSA-w8gw-qm8p-j9j3.json"