Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4g29-fccr-p59w

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Reflected Cross-site Scripting in Shopware storefront

Impact

Not-stored XSS in storefront. Request parameter were directly assigned to the template, so that malicious code could be send via an URL.

Patches

We recommend updating to the current version 5.7.9. You can get the update to 5.7.9 regularly via the Auto-Updater or directly via the download overview. https://www.shopware.com/en/changelog-sw5/#5-7-9

For older versions you can use the Security Plugin: https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html

References

https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022

Пакеты

Наименование

shopware/shopware

composer
Затронутые версииВерсия исправления

< 5.7.9

5.7.9

EPSS

Процентиль: 71%
0.0066
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

EPSS

Процентиль: 71%
0.0066
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79