Description

CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the shop owner (admin) approves the testimonial, the script executes in the context of any user visiting the testimonial page. Because the session cookies are not marked with the `HttpOnly` flag, they can be exfiltrated by the attacker — potentially leading to account takeover. Version 1.1.0.3 fixes the issue.

INFO

Published Date :

2025-06-02T11:00:20.730Z

Last Modified :

2025-06-02T13:05:57.212Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-47289 vulnerability.

Vendors Products
Phoenixcart
  • Ce Phoenix Cart
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-47289.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact