VDB
Sign up
MEDIUM5.4

GHSA-fxf3-wx3c-76pf

Shopware vulnerable to Cross-site Scripting

Quick fix

GHSA-fxf3-wx3c-76pf — shopware/platform: upgrade to the fixed version with the command below.

composer require shopware/platform:^6.2.3

Details

In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/platform
Introduced in: 0Fixed in: 6.2.3
Fixcomposer require shopware/platform:^6.2.3

References