Intel

AIKIDO-2025-10929

akeneo/module-magento2-connector-community is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 11, 2025

65

Medium Risk

This Affects:

PHPakeneo/module-magento2-connector-community
100.1.0 - 105.1.1
Fixed in 105.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a Cross-Site Scripting (XSS) vulnerability due to unescaped template output in HTML tags, attributes, and logging methods, which was addressed by adding the MagentoFrameworkEscaper library to properly escape HTML. Before this fix, user-supplied input was not effectively sanitized, allowing attackers to inject malicious scripts. An attacker could exploit this by submitting crafted input that, when rendered by the application, executes arbitrary JavaScript in the victim's browser.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

akeneo/module-magento2-connector-community is vulnerable to Cross-Site Scripting (XSS) in versions 100.1.0 - 105.1.1.

How to fix this

Upgrade the akeneo/module-magento2-connector-community library to the patch version.