CVE-2022-31148: Persistent cross site scripting in customer module in Shopware
Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31148?
The severity of CVE-2022-31148 is medium with a CVSS score of 5.4.
How does CVE-2022-31148 affect Shopware?
CVE-2022-31148 is a persistent cross-site scripting (XSS) vulnerability that exists in the customer module of Shopware versions from 5.7.0 to 5.7.14.
How can I fix CVE-2022-31148 in Shopware?
To fix CVE-2022-31148, users are recommended to update to the current version 5.7.14 of Shopware.
Where can I find more information about CVE-2022-31148?
You can find more information about CVE-2022-31148 in the Shopware security update 07/2022 and the GitHub commit and advisory.