← Back to all sparks
S

Solidus

E-COMM
Velocity2.5

Open source Ruby on Rails e-commerce platform

Solidus admin 0.4.1 closes a stored XSS on a customer page.

ecommerceadmin-uisecurity-patchrails
◆Current state
The one tracked Solidus release is a security patch to solidus_admin, the newer admin interface. Product names, variant options and SKUs were rendered as raw HTML on a customer's Items Purchased page, allowing stored cross-site scripting; 0.4.1 escapes them.
◆Where it's heading
A single security patch doesn't establish a direction. It does show solidus_admin is in production use across 0.3.0–0.4.0 and is being maintained with point releases.
◆Prediction
One entry is not enough to predict the next move; more tracked releases are needed.

◆Recent moves

  1. 2d ago

    solidus_admin 0.4.1 fixes stored XSS on Items Purchased page

    Escapes product names, variant options and SKUs that were rendered as raw HTML on the customer Items Purchased page. Stores on solidus_admin 0.3.0–0.4.0 should upgrade, but it adds no capability.

    View source ↗