Product
An unauthenticated stored XSS vulnerability in Concrete CMS Community Store versions prior to 2.7.8 allows attackers to execute malicious scripts in manager sessions via order fields.