—
PYSEC-2021-350
Quick fix
PYSEC-2021-350 — shuup: upgrade to the fixed version with the command below.
pip install --upgrade 'shuup>=75714c37e32796eb7cbb0d977af5bcaa26573588'Details
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/shuup
Introduced in:
0Fixed in: 75714c37e32796eb7cbb0d977af5bcaa26573588Fix
pip install --upgrade 'shuup>=75714c37e32796eb7cbb0d977af5bcaa26573588'