CVE-2021-37710: Cross-Site Scripting via SVG media files
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shopwareto a version that resolves this vulnerability.Fixed in 6.4.3.1 - Compensating control
For older Shopware versions 6.1, 6.2, and 6.3 (prior to 6.4.3.1), apply the corresponding security measures via the available plugin as a workaround for the Cross-Site Scripting via SVG media files vulnerability.
Event History
Frequently Asked Questions
What is CVE-2021-37710?
CVE-2021-37710 is a Cross-Site Scripting vulnerability in Shopware eCommerce platform versions prior to 6.4.3.1.
How severe is CVE-2021-37710?
CVE-2021-37710 has a severity score of 5.4, which is considered high.
How does CVE-2021-37710 affect Shopware?
CVE-2021-37710 affects Shopware versions prior to 6.4.3.1, allowing for Cross-Site Scripting attacks via SVG media files.
How can I fix CVE-2021-37710?
To fix CVE-2021-37710, it is recommended to update to Shopware version 6.4.3.1, which contains a patch for the vulnerability.
Are there any workarounds for older versions of Shopware?
Yes, for older versions (6.1, 6.2, and 6.3), corresponding security measures are available through a plugin.