Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Authenticated Stored XSS
Vulnerability Description
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Shopware 跨站脚本漏洞
Vulnerability Description
Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware platform存在跨站脚本漏洞,该漏洞源于Shopware 5.6.10版本及之前版本存在通过身份验证的存储型XSS漏洞。
CVSS Information
N/A
Vulnerability Type
N/A