Shopware before 5.5.8 contains a reflected cross-site scripting (XSS) caused by unsanitized query string parameters in the backend/Login or backend/Login/load/ URI, letting attackers execute arbitrary scripts in the context of the victim's browser, exploit requires sending crafted URL to the victim.
id: CVE-2019-12935
info:
name: Shopware < 5.5.8 - Cross-Site Scripting
author: pussycat0x
sev
...