
We found results for “”
CVE-2022-24873
Good to know:

Date: April 28, 2022
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version shopware/shopware - v5.0.3-RC1;shopware/shopware - v5.5.0;shopware/shopware - dev-dependabot/composer/ramsey/uuid-4.3.1;shopware/shopware - v5.2.0-BETA1;shopware/shopware - v5.0.4-RC1;shopware/shopware - dev-dependabot/composer/recovery/common/voku/anti-xss-4.1.42;shopware/shopware - dev-dependabot/composer/vendor-bin/cs-fixer/composer-65e32c6de6;shopware/shopware - no_fix;shopware/shopware - dev-dependabot/composer/symfony/web-link-5.2.12;shopware/shopware - dev-dependabot/npm_and_yarn/themes/grunt-contrib-uglify-5.2.2;shopware/shopware - dev-dependabot/composer/symfony/validator-5.0.11;shopware/shopware - v5.1.3-RC1;shopware/shopware - dev-dependabot/composer/symfony/options-resolver-5.4.21;shopware/shopware - v5.7.4;shopware/shopware - dev-dependabot/npm_and_yarn/themes/md5-file-5.0.0;shopware/shopware - dev-dependabot/composer/cocur/slugify-4.4.1;shopware/shopware - v5.6.0-RC1;shopware/shopware - v5.2.3;shopware/shopware - v5.6.0;shopware/shopware - v5.5.0-RC1;shopware/shopware - dev-ntr/check-for-mysql-availability;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/Frontend/Responsive/json5-2.2.3;communiacs/shopware - 5.6.10;communiacs/shopware - dev-dependabot/composer/symfony/http-kernel-4.4.50;communiacs/shopware - 5.2.21-dev;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/json5-1.0.2;communiacs/shopware - 5.5.1;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/path-parse-1.0.7;communiacs/shopware - 5.5.7;wlwwt/shopware - 5.5.1;wlwwt/shopware - 5.2.21-dev;wlwwt/shopware - no_fix;cus/shopware - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | NONE |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |