icon

We found results for “

CVE-2022-24873

Good to know:

icon

Date: April 28, 2022

Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version shopware/shopware - v5.0.3-RC1;shopware/shopware - v5.5.0;shopware/shopware - dev-dependabot/composer/ramsey/uuid-4.3.1;shopware/shopware - v5.2.0-BETA1;shopware/shopware - v5.0.4-RC1;shopware/shopware - dev-dependabot/composer/recovery/common/voku/anti-xss-4.1.42;shopware/shopware - dev-dependabot/composer/vendor-bin/cs-fixer/composer-65e32c6de6;shopware/shopware - no_fix;shopware/shopware - dev-dependabot/composer/symfony/web-link-5.2.12;shopware/shopware - dev-dependabot/npm_and_yarn/themes/grunt-contrib-uglify-5.2.2;shopware/shopware - dev-dependabot/composer/symfony/validator-5.0.11;shopware/shopware - v5.1.3-RC1;shopware/shopware - dev-dependabot/composer/symfony/options-resolver-5.4.21;shopware/shopware - v5.7.4;shopware/shopware - dev-dependabot/npm_and_yarn/themes/md5-file-5.0.0;shopware/shopware - dev-dependabot/composer/cocur/slugify-4.4.1;shopware/shopware - v5.6.0-RC1;shopware/shopware - v5.2.3;shopware/shopware - v5.6.0;shopware/shopware - v5.5.0-RC1;shopware/shopware - dev-ntr/check-for-mysql-availability;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/Frontend/Responsive/json5-2.2.3;communiacs/shopware - 5.6.10;communiacs/shopware - dev-dependabot/composer/symfony/http-kernel-4.4.50;communiacs/shopware - 5.2.21-dev;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/json5-1.0.2;communiacs/shopware - 5.5.1;communiacs/shopware - dev-dependabot/npm_and_yarn/themes/path-parse-1.0.7;communiacs/shopware - 5.5.7;wlwwt/shopware - 5.5.1;wlwwt/shopware - 5.2.21-dev;wlwwt/shopware - no_fix;cus/shopware - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us