Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18526
HistoryMar 11, 2022 - 12:00 a.m.

Shopware Cross-Site Scripting Vulnerability (CNVD-2022-18526)

2022-03-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
5

0.001 Low

EPSS

Percentile

30.8%

Shopware is a set of open source e-commerce software from the German company Shopware.Shopware suffers from a cross-site scripting vulnerability that stems from the program’s lack of data validation filtering of user-supplied and output data. An attacker could exploit this vulnerability to inject JavaScript code via the credential code form.

CPENameOperatorVersion
Shopware Shopware <6.eq4.8.1

0.001 Low

EPSS

Percentile

30.8%