First published: Mon Aug 01 2022(Updated: )
Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | >=5.7.0<5.7.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-31148 is medium with a CVSS score of 5.4.
CVE-2022-31148 is a persistent cross-site scripting (XSS) vulnerability that exists in the customer module of Shopware versions from 5.7.0 to 5.7.14.
To fix CVE-2022-31148, users are recommended to update to the current version 5.7.14 of Shopware.
You can find more information about CVE-2022-31148 in the Shopware security update 07/2022 and the GitHub commit and advisory.