First published: Tue Oct 26 2021(Updated: )
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file will protect against cross-site scripting in this case. There is also a config for those using nginx as a server. The plugin and the configs can be found on the GitHub Security Advisory page for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | <5.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41188 is a cross-site scripting vulnerability in Shopware, an open-source e-commerce software.
CVE-2021-41188 has a severity level of 5.4, which is considered medium.
To fix CVE-2021-41188, upgrade your Shopware installation to version 5.7.6 or later.
You can use the security plugin or add a particular config to the `.htaccess` file as workarounds for CVE-2021-41188.
You can find more information about CVE-2021-41188 in the Shopware documentation and the official GitHub repository.