CVE-2022-31057: Authenticated Stored XSS in Shopware Administration
Published Jun 27, 2022
·Updated
Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
1 affected component
Shopware Shopware>=5.0.0<5.7.12
Remediation
Event History
Jun 27, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31057.
2
What is the severity of CVE-2022-31057?
The severity of CVE-2022-31057 is medium.
3
What is the affected software for CVE-2022-31057?
The affected software for CVE-2022-31057 is Shopware version 5 prior to version 5.7.12.
4
What is the recommended action for CVE-2022-31057?
Users are advised to upgrade Shopware to version 5.7.12 or later.
5
Are there any known workarounds for CVE-2022-31057?
There are no known workarounds for CVE-2022-31057.