CVE-2019-12935: XSS
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12935?
CVE-2019-12935 is a vulnerability in Shopware before version 5.5.8 that allows for cross-site scripting (XSS) attacks via the query string to the backend/Login or backend/Login/load/ URI.
How severe is CVE-2019-12935?
CVE-2019-12935 has a severity rating of medium and a CVSS score of 6.1.
How can I fix CVE-2019-12935?
To fix CVE-2019-12935, you need to update your Shopware installation to version 5.5.8 or higher.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Where can I find more information about CVE-2019-12935?
You can find more information about CVE-2019-12935 on the NIST website (https://nvd.nist.gov/vuln/detail/CVE-2019-12935) and the Shopware changelog (https://www.shopware.com/en/changelog/#5-5-8).