CVE-2022-24873: Non-Stored Cross-site Scripting in Shopware storefront
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24873?
CVE-2022-24873 is a vulnerability in Shopware e-commerce software platform that allows non-stored cross-site scripting in the storefront.
What is the severity of CVE-2022-24873?
CVE-2022-24873 has a severity level of 6.1, which is considered medium.
What is the affected software version of CVE-2022-24873?
Versions of Shopware prior to 5.7.9 are affected by CVE-2022-24873.
How can I mitigate CVE-2022-24873 vulnerability?
Users of older Shopware versions can attempt to mitigate the vulnerability by using the Shopware security plugin.
Where can I find more information about CVE-2022-24873?
You can find more information about CVE-2022-24873 in the Shopware documentation, security advisories, and changelog.