packetstormsecurity.com
http://packetstormsecurity.com/files/153145/Shopware-5.5.6-Cross-Site-Scripting.html CVE-2019-12935
HIGHNuclei
Shopware Cross-site Scripting Vulnerability
Record summary
CVE-2019-12935 has a selected CVSS score of 7.4 (high); EIP currently links 1 Nuclei template.
Description
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
shopware/shopwareBrowse Packagist / shopware/shopware | GitHub Advisory | Before 5.5.8 · Fixed in 5.5.8 | affected |
Nuclei templates
1ProjectDiscoveryHIGHShopware < 5.5.8 - Cross-Site ScriptingCVSS 7.4
Shopware before 5.5.8 contains a reflected cross-site scripting (XSS) caused by unsanitized query string parameters in the backend/Login or backend/Login/load/ URI, letting attackers execute arbitrary scripts in the context of the victim's browser, exploit requires sending crafted URL to the victim.
Impact
Attackers can execute malicious scripts in the victim's browser, potentially leading to session hijacking or defacement.
Remediation
Update to version 5.5.8 or later.
WeaknessesCWE-79
Authorspussycat0x
Template tagscvecve2019shopwarexss
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
https://www.miggo.io/vulnerability-database/cve/CVE-2019-12935 https://nvd.nist.gov/vuln/detail/CVE-2019-12935
Source: ProjectDiscovery
References
520190624 Re: Multiple Cross-site Scripting Vulnerabilities in Shopware 5.5.6mailing list
http://seclists.org/fulldisclosure/2019/Jun/32 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-12935 netsparker.com
https://www.netsparker.com/web-applications-advisories/ns-19-004-cross-site-scripting-in-shopware shopware.com
https://www.shopware.com/en/changelog