Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-58390
HistoryJun 30, 2022 - 12:00 a.m.

Shopware Cross-Site Scripting Vulnerability (CNVD-2022-58390)

2022-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.001 Low

EPSS

Percentile

33.6%

Shopware is a set of open source e-commerce software from the German company Shopware.A cross-site scripting vulnerability exists in versions of Shopware prior to 5.7.12, which stems from a lack of data validation filtering of user-supplied and output data during login authentication. An attacker could exploit the vulnerability to execute JavaScript code on the client side.

CPENameOperatorVersion
shopware shopwarelt5.7.12

0.001 Low

EPSS

Percentile

33.6%