CE Phoenix Stored Cross-Site Scripting Vulnerability in Currencies Administration Panel

Vulnerability

A stored cross-site scripting vulnerability has been identified in CE Phoenix version 3.0.1, specifically within the currencies administration panel. This vulnerability allows attackers to inject malicious scripts that are executed when administrators view the currencies page. The XSS payloads can be inserted into the title field.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.

Reproduction

To reproduce this vulnerability, log into the admin panel and navigate to the currencies administration page. Click to edit an existing currency and enter a script payload into the title field. After saving the changes, return to the currencies page to see the alert generated by the executed script.

Added: Dec 11, 2025, 10:35 PM
Updated: Dec 11, 2025, 10:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.9
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.