{"id":"CVE-2026-42458","aliases":["GHSA-x8jv-q8j2-487c"],"url":"https://o3.security/vulnerability/CVE-2026-42458","summary":"Magento LTS: Reflected XSS - Import -> Data Flow (profiles)","details":"A reflected XSS vulnerability was found under admin panel ->  System -> Import/Export -> Dataflow -  Profiles.\n\n## Steps to produce\n\n+ Login to  the admin panel \n\n+ Go to the path   `System -> Import/Export -> Dataflow -  Profiles`\n\n+ Select profile direction as `Import`.\n\n+ Click on `Import Customers` \n\n+ Upload the file.\n\nFile Link: [customer_20260212_204335.csv](https://github.com/user-attachments/files/25629638/customer_20260212_204335.csv)\n\n+ Go back to `Run profile`.\n\n+ Select the uploaded file and Click on `Run in Popup`.\n\n+ One can see a URL like this \n\n```\nhttps://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/import-20260215151125-1_customer_20260212_204335.csv/\n```\n\n\n+ One can see the filename getting reflection in HTML tags.\n\n+ Inject an HTML tag and observe.\n\n```\nhttps://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/\"><h3>hacked</h3>/\n``` \n\n<img width=\"1796\" height=\"302\" alt=\"image (3)\" src=\"https://github.com/user-attachments/assets/502330b0-fa73-4b90-a81f-6216a98e474a\" />\n\n+ One can see the tag is getting executed.\n\n+  Proceed for XSS.\n\n```\nhttps://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/%3CScRiPt%20%3Eprompt(document.cookie)%3C%2FScRiPt%3E\n```\n\n<img width=\"1670\" height=\"562\" alt=\"image (4)\" src=\"https://github.com/user-attachments/assets/98a75081-fa8c-4483-9078-0ab5e7e14e4d\" />\n\n\n+ There is an XSS popup.\n\n## Impact\n\nCookie stealing, JS deface, many more","published":"2026-05-15T17:02:42.878Z","modified":"2026-08-12T03:51:47.953987905Z","cvss":null,"epss":{"score":0.00258,"percentile":0.17444,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"20.18.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42458.json"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-x8jv-q8j2-487c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42458"},{"type":"PACKAGE","url":"https://github.com/OpenMage/magento-lts"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.953987905Z"}}