PT-2022-20563 · Shopware · Shopware

Published

2022-07-27

·

Updated

2022-08-05

·

CVE-2022-31148

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions 5.7.0 through 5.7.13
Description A persistent cross-site scripting (XSS) issue exists in the customer module. This allows for malicious scripts to be executed in the context of the user's session. Users are recommended to update to the current version to resolve the issue. There are no known workarounds for this problem.
Recommendations For versions 5.7.0 through 5.7.13, update to version 5.7.14 via the Auto-Updater or directly via the download overview. For older versions, consider using the Security Plugin as a temporary mitigation measure until a more permanent solution can be applied. As a temporary workaround, consider restricting access to the customer module until the update to version 5.7.14 can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31148
GHSA-5834-XV5Q-CGFW

Affected Products

Shopware