Authenticated Stored XSS in shopware/shopware
Moderate severity
GitHub Reviewed
Published
Oct 26, 2021
in
shopware5/shopware
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 26, 2021
Reviewed
Oct 26, 2021
Published to the GitHub Advisory Database
Oct 27, 2021
Last updated
Feb 1, 2023
Impact
Authenticated Stored XSS in Administration
Patches
Use the Security Plugin:
https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html
Workarounds
If you cannot use the security plugin, add the following config to your
.htaccess
fileIf you are using nginx as server config, you can add the following to your configuration:
References
https://docs.shopware.com/en/shopware-5-en/sicherheitsupdates/security-update-10-2021
References