CVE-2022-24873

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24873
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-24873.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-24873
Aliases
Withdrawn
2024-05-08T06:51:50.179108Z
Published
2022-04-28T14:15:00Z
Modified
2023-11-01T04:58:11.327295Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

References

Affected packages

Git / github.com/shopware/shopware

Affected ranges

Type
GIT
Repo
https://github.com/shopware/shopware
Events

Affected versions

1.*

1.0.2
1.0.8

4.*

4.3.3
4.3.4
4.3.5
4.3.6

v5.*

v5.0.0
v5.0.0-BETA2
v5.0.0-RC1
v5.0.0-RC2
v5.0.0-RC3
v5.0.0-WORKSHOP
v5.0.1
v5.0.2
v5.0.2-RC1
v5.0.3
v5.0.3-RC1
v5.0.4
v5.0.4-RC1
v5.1.0
v5.1.0-RC2
v5.1.0-RC3
v5.1.1
v5.1.2
v5.1.2-RC1
v5.1.2-RC2
v5.1.3
v5.1.3-RC1
v5.1.4
v5.1.5
v5.1.6
v5.2.0
v5.2.0-BETA1
v5.2.0-RC1
v5.2.0-RC2
v5.2.0-RC3
v5.2.1
v5.2.10
v5.2.11
v5.2.12
v5.2.13
v5.2.14
v5.2.15
v5.2.16
v5.2.17
v5.2.18
v5.2.19
v5.2.2
v5.2.20
v5.2.21
v5.2.22
v5.2.23
v5.2.24
v5.2.25
v5.2.26
v5.2.27
v5.2.3
v5.2.4
v5.2.5
v5.2.6
v5.2.7
v5.2.8
v5.2.9
v5.3.0
v5.3.0-RC1
v5.3.0-RC2
v5.3.1
v5.3.2
v5.3.3
v5.3.4
v5.3.5
v5.3.6
v5.3.7
v5.4.0
v5.4.0-RC1
v5.4.1
v5.4.2
v5.4.3
v5.4.4
v5.4.5
v5.4.6
v5.5.0
v5.5.0-BETA1
v5.5.0-RC1
v5.5.1
v5.5.10
v5.5.2
v5.5.3
v5.5.4
v5.5.5
v5.5.6
v5.5.7
v5.5.8
v5.5.9
v5.6.0
v5.6.0-RC1
v5.6.1
v5.6.2
v5.6.3
v5.6.5
v5.6.6
v5.6.7
v5.6.8
v5.7.0
v5.7.0-RC1
v5.7.0-RC2
v5.7.1
v5.7.3
v5.7.4
v5.7.5
v5.7.6
v5.7.8