Neto E-Commerce CMS Cross-Site Scripting Vulnerability Allowing Privilege Escalation

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Neto E-Commerce CMS versions 6.313.0 prior to 6.3115. This vulnerability allows remote attackers to inject and execute arbitrary JavaScript by exploiting the kw parameter in the search functionality. The issue arises from improper sanitization of user input, enabling not only cross-site scripting but also cross-site request forgery (CSRF) attacks, account takeover (ATO) on sites with user sessions, and potential phishing or defacement attacks.

Impact

Exploitation of this vulnerability allows for arbitrary JavaScript execution in the context of the victim's browser, creating opportunities for cross-site request forgery (CSRF) attacks, account takeover (ATO) on sites with user sessions, and phishing or UI defacement attacks.

Reproduction

To reproduce this vulnerability, visit a Neto CMS site running a vulnerable version and include a crafted payload in the kw parameter of the search URL. The payload can be a JavaScript expression, such as one that calls the prompt or confirm functions. Once the URL is accessed, the injected script will execute in the browser.

Added: Oct 1, 2025, 6:20 PM
Updated: Oct 1, 2025, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.