Record summary

CVE-2019-12935 has a selected CVSS score of 7.4 (high); EIP currently links 1 Nuclei template.

Description

Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 5.5.8 · Fixed in 5.5.8affected

Nuclei templates

1
ProjectDiscoveryHIGHShopware < 5.5.8 - Cross-Site ScriptingCVSS 7.4

Shopware before 5.5.8 contains a reflected cross-site scripting (XSS) caused by unsanitized query string parameters in the backend/Login or backend/Login/load/ URI, letting attackers execute arbitrary scripts in the context of the victim's browser, exploit requires sending crafted URL to the victim.

Impact

Attackers can execute malicious scripts in the victim's browser, potentially leading to session hijacking or defacement.

Remediation

Update to version 5.5.8 or later.

WeaknessesCWE-79
Authorspussycat0x
Template tagscvecve2019shopwarexss
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Source: ProjectDiscovery

References

5