Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52997 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 05 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Optimizely
Optimizely configured Commerce |
|
| CPEs | cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Optimizely
Optimizely configured Commerce |
Wed, 18 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 18 Dec 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-18T15:09:37.534Z
Reserved: 2024-12-18T00:00:00.000Z
Link: CVE-2024-56175
Updated: 2024-12-18T15:09:14.493Z
Status : Analyzed
Published: 2024-12-18T06:15:24.087
Modified: 2025-06-05T20:59:27.300
Link: CVE-2024-56175
No data.
OpenCVE Enrichment
No data.
EUVD