Vulnerabilities
Vulnerable Software
Shopware:  >> Shopware  >> 5.4.0  Security Vulnerabilities
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
CVSS Score
5.4
EPSS Score
0.003
Published
2020-07-28
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
CVSS Score
7.5
EPSS Score
0.01
Published
2020-07-28
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
CVSS Score
7.4
EPSS Score
0.005
Published
2019-06-23
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
CVSS Score
6.5
EPSS Score
0.3
Published
2019-06-13
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
CVSS Score
8.8
EPSS Score
0.006
Published
2019-01-15


Contact Us

Shodan ® - All rights reserved