Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/shopware/platform/security/advisories/GHSA-fc38-mxwr-pfhx | third party advisory |
https://github.com/shopware/platform/commit/abe9f69e1f667800f974acccd3047b4930e4b423 | third party advisory patch |