CVE-2026-7170 TPVEnlanube 存储型 XSS 漏洞
影响已认证攻击者可注入恶意脚本并在他人浏览器中执行
CVE-2026-7170 是 TPVEnlanube 组件中的存储型跨站脚本(XSS)漏洞。攻击者可通过 VirtueMart 商店管理端点的 vendor_store_name 参数注入恶意脚本,脚本被持久化存储后在其他用户浏览页面时执行。
影响范围
受影响组件为 TPVEnlanube,涉及端点 /administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID] 的 vendor_store_name 参数。具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于存储型 XSS,成因是应用未对用户提交的 vendor_store_name 参数进行充分的输入过滤或输出编码。攻击者提交含恶意脚本的内容后,脚本被保存到服务端,当管理员或其他用户访问相关页面时在浏览器中执行。
利用条件与风险
利用需攻击者具备已认证身份并能访问商店添加/编辑功能,属于后台存储型 XSS,可导致会话劫持或后台操作被劫持,实战风险中等。
修复建议
官方修复方案暂无公开信息,建议关注厂商更新并及时升级;临时缓解可对 vendor_store_name 等参数进行严格输入校验与输出编码,并限制后台访问权限。
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
* CVE-2026-7170: parameter ‘vendor_store_name’ in the endpoint ‘/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]’.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users’ browsers without their consent.