Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6w82-v552-wjw2 | Shopware Storefront Reflected XSS in Storefront Login Page |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopware
Shopware shopware |
|
| Vendors & Products |
Shopware
Shopware shopware |
Thu, 11 Dec 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1. | |
| Title | Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-11T19:00:14.044Z
Reserved: 2025-12-09T18:36:41.331Z
Link: CVE-2025-67648
Updated: 2025-12-11T19:00:09.520Z
Status : Received
Published: 2025-12-11T00:16:23.557
Modified: 2025-12-11T00:16:23.557
Link: CVE-2025-67648
No data.
OpenCVE Enrichment
Updated: 2025-12-11T15:17:02Z
Github GHSA