BlackKite: Home
Menu

PUBLISHED DATE: June 2, 2025CVE-2025-47289:
Cross-Site Scripting Vulnerability

CVSS:
6.3
EPSS:
2.90%
Exploitability:
2.1
In KEV:
No
Description

CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the shop owner (admin) approves the testimonial, the script executes in the context of any user visiting the testimonial page. Because the session cookies are not marked with the `HttpOnly` flag, they can be exfiltrated by the attacker — potentially leading to account takeover. Version 1.1.0.3 fixes the issue.

Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2025-47289, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2025-47289 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?