CVE-2023-46499
Description
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
EverShop before v1.0.0-rc.5 contains a stored XSS vulnerability in the Admin Panel, exploitable via product creation and user registration.
EverShop versions prior to 1.0.0-rc.5 are vulnerable to a stored cross-site scripting (XSS) issue within the Admin Panel [1][3]. The vulnerability stems from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are persistently stored on the server [3]. Affected inputs include fields used when creating new products and during user registration [3].
The attack surface is broad: an unauthenticated remote attacker can inject a crafted script during the user registration process, which will later be executed when an administrator visits the users' section of the Admin Panel [3]. Additionally, authenticated users with product creation privileges can store malicious code in product fields [3]. The vulnerability does not require any special network position beyond web access [1].
Successful exploitation allows an attacker to obtain sensitive information, perform actions on behalf of the administrator, and potentially achieve account takeover [1][3]. This can lead to full compromise of the e-commerce backend and the data it handles.
A fix was implemented in pull request #244 and released in version 1.0.0-rc.5 [4]. Users should upgrade to this version or later to mitigate the risk [3].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@evershop/evershopnpm | < 1.0.0-rc.5 | 1.0.0-rc.5 |
Affected products
2- EverShop/EverShop NPMdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/advisories/GHSA-gjj8-m83c-qv9hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-46499ghsaADVISORY
- devhub.checkmarx.com/cve-details/Cx0f8b38be-d5deghsaWEB
- devhub.checkmarx.com/cve-details/cve-2023-46499ghsaWEB
- github.com/evershopcommerce/evershop/pull/244ghsaWEB
- devhub.checkmarx.com/cve-details/Cx0f8b38be-d5de/mitre
- devhub.checkmarx.com/cve-details/cve-2023-46499/mitre
News mentions
0No linked articles in our index yet.