Summary
Axis Commerce is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie- based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Axis Commerce versions 0.8.1 and prior are vulnerable.
References