Discussions
Join us for complimentary one-day events around the world and step into a future fueled by AI and limitless potential. Explore new breakthroughs, sharpen your skills, and connect with experts who are shaping what’s next. Experience bold keynotes, interactive learning, and connections that span the global NetSuite community. Discover what's next at SuiteConnect Tour 2026.
Elbrus : Cross-site Scripting Issue
SuiteCommerce Advanced sites may be vulnerable to Cross-site Scripting (XSS) issues. XSS vulnerability means malicious third parties could use your SuiteCommerce Advanced website to attack your users. If you are vulnerable, you must apply a patch to your SuiteCommerce Advanced code to protect your site.
Does this issue apply to my website?
If you are using an unpatched version of one of the below Suite Commerce Advanced (SCA) releases, you are vulnerable.
The SCA releases listed below contain an XSS vulnerability in the original template code. Once you install an SCA template, you likely modified it for your specific website needs; we have not evaluated your specific code to determine whether you have modified the original reference code in a way which would have previously resolved this vulnerability.
Regards,
@Robert Nedelkow-Oracle | NetSuite Support Community Administrator
In case you know someone who is new to NetSuite, we encourage you to direct them to our newly launched "New to NetSuite" page. This page is specifically designed to offer them information and guidance and help them make the most out of their NetSuite journey. Click here for more details.
