CVE-2021-41188: Authenticated Stored XSS in Administration
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the .htaccess file will protect against cross-site scripting in this case. There is also a config for those using nginx as a server. The plugin and the configs can be found on the GitHub Security Advisory page for this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-41188?
CVE-2021-41188 is a cross-site scripting vulnerability in Shopware, an open-source e-commerce software.
How severe is CVE-2021-41188?
CVE-2021-41188 has a severity level of 5.4, which is considered medium.
How can I fix CVE-2021-41188?
To fix CVE-2021-41188, upgrade your Shopware installation to version 5.7.6 or later.
What are the workarounds for CVE-2021-41188?
You can use the security plugin or add a particular config to the `.htaccess` file as workarounds for CVE-2021-41188.
Where can I find more information about CVE-2021-41188?
You can find more information about CVE-2021-41188 in the Shopware documentation and the official GitHub repository.