VYPR
Moderate severityNVD Advisory· Published Dec 8, 2023· Updated Nov 26, 2024

CVE-2023-46499

CVE-2023-46499

Description

Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

EverShop before v1.0.0-rc.5 contains a stored XSS vulnerability in the Admin Panel, exploitable via product creation and user registration.

EverShop versions prior to 1.0.0-rc.5 are vulnerable to a stored cross-site scripting (XSS) issue within the Admin Panel [1][3]. The vulnerability stems from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are persistently stored on the server [3]. Affected inputs include fields used when creating new products and during user registration [3].

The attack surface is broad: an unauthenticated remote attacker can inject a crafted script during the user registration process, which will later be executed when an administrator visits the users' section of the Admin Panel [3]. Additionally, authenticated users with product creation privileges can store malicious code in product fields [3]. The vulnerability does not require any special network position beyond web access [1].

Successful exploitation allows an attacker to obtain sensitive information, perform actions on behalf of the administrator, and potentially achieve account takeover [1][3]. This can lead to full compromise of the e-commerce backend and the data it handles.

A fix was implemented in pull request #244 and released in version 1.0.0-rc.5 [4]. Users should upgrade to this version or later to mitigate the risk [3].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@evershop/evershopnpm
< 1.0.0-rc.51.0.0-rc.5

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.