CVE-2022-48150
MEDIUMShopware 5.5.10 - Cross-Site Scripting via Recovery/Install URI
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-48150. PoCs published by SahilH4ck4you.
AI-analyzed exploit summary The repository contains a README describing a reflected XSS vulnerability in Shopware 5, with a reference to a PoC video but no actual exploit code or technical details provided.
Description
Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
Exploits (2)
The repository contains a README describing a reflected XSS vulnerability in Shopware 5, with a reference to a PoC video but no actual exploit code or technical details provided.
The repository claims to demonstrate a reflected XSS vulnerability in Shopware 5 but provides no technical details or exploit code. It instead directs users to an external video, which is a common tactic for suspicious or low-quality PoCs.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N