Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file will protect against cross-site scripting in this case. There is also a config for those using nginx as a server. The plugin and the configs can be found on the GitHub Security Advisory page for this vulnerability.

Project Subscriptions

Vendors Products
Shopware Subscribe
Shopware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2156 Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file will protect against cross-site scripting in this case. There is also a config for those using nginx as a server. The plugin and the configs can be found on the GitHub Security Advisory page for this vulnerability.
Github GHSA Github GHSA GHSA-4p3x-8qw9-24w9 Authenticated Stored XSS in shopware/shopware
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T03:08:31.242Z

Reserved: 2021-09-15T00:00:00

Link: CVE-2021-41188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-26T15:15:10.607

Modified: 2024-11-21T06:25:43.210

Link: CVE-2021-41188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses