CVE-2022-24873 Information
Jun 07, 2022
cve
Description
Shopware is an open source e-commerce software platform. Prior to version 5.7.9 Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022 https://www.shopware.com/en/changelog-sw5/#5-7-9 https://github.com/shopware/shopware/security/advisories/GHSA-4g29-fccr-p59w
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: