VDB
Sign up
—

PYSEC-2021-350

Quick fix

PYSEC-2021-350 — shuup: upgrade to the fixed version with the command below.

pip install --upgrade 'shuup>=75714c37e32796eb7cbb0d977af5bcaa26573588'

Details

In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/shuup
Introduced in: 0Fixed in: 75714c37e32796eb7cbb0d977af5bcaa26573588
Fixpip install --upgrade 'shuup>=75714c37e32796eb7cbb0d977af5bcaa26573588'

References