Lucene search

K
cve[email protected]CVE-2017-15374
HistoryOct 16, 2017 - 4:29 a.m.

CVE-2017-15374

2017-10-1604:29:00
CWE-79
web.nvd.nist.gov
42
shopware
cross site scripting
content management system
backend
remote attack
injection
persistent execution
privileged accounts
vulnerability
cve-2017-15374

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.03 Low

EPSS

Percentile

91.0%

Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent execution in the customer and orders section of the backend. The execution occurs in the administrator backend listing when processing a preview of the customers (kunden) or orders (bestellungen). The injection can be performed interactively via user registration or by manipulation of the order information inputs. The issue can be exploited by low privileged user accounts against higher privileged (admin or moderator) accounts.

Affected configurations

NVD
Node
shopwareshopwareMatch5.2.5
OR
shopwareshopwareMatch5.2.6
OR
shopwareshopwareMatch5.2.7
OR
shopwareshopwareMatch5.2.8
OR
shopwareshopwareMatch5.2.9
OR
shopwareshopwareMatch5.2.10
OR
shopwareshopwareMatch5.2.11
OR
shopwareshopwareMatch5.2.12
OR
shopwareshopwareMatch5.2.13
OR
shopwareshopwareMatch5.2.14
OR
shopwareshopwareMatch5.2.15
OR
shopwareshopwareMatch5.2.16
OR
shopwareshopwareMatch5.2.17
OR
shopwareshopwareMatch5.2.18
OR
shopwareshopwareMatch5.2.19
OR
shopwareshopwareMatch5.2.20
OR
shopwareshopwareMatch5.2.21
OR
shopwareshopwareMatch5.2.22
OR
shopwareshopwareMatch5.2.23
OR
shopwareshopwareMatch5.2.24
OR
shopwareshopwareMatch5.2.25
OR
shopwareshopwareMatch5.2.26
OR
shopwareshopwareMatch5.2.27
OR
shopwareshopwareMatch5.3.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.03 Low

EPSS

Percentile

91.0%