In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Optimizely
Optimizely configured Commerce |
|
CPEs | cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:* | |
Vendors & Products |
Optimizely
Optimizely configured Commerce |
Wed, 18 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Wed, 18 Dec 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-18T00:00:00
Updated: 2024-12-18T15:09:37.534Z
Reserved: 2024-12-18T00:00:00
Link: CVE-2024-56175

Updated: 2024-12-18T15:09:14.493Z

Status : Analyzed
Published: 2024-12-18T06:15:24.087
Modified: 2025-06-05T20:59:27.300
Link: CVE-2024-56175

No data.