MEDIUM5.4
GHSA-fxf3-wx3c-76pf
Shopware vulnerable to Cross-site Scripting
Quick fix
GHSA-fxf3-wx3c-76pf — shopware/platform: upgrade to the fixed version with the command below.
composer require shopware/platform:^6.2.3Details
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/shopware/platform
Introduced in:
0Fixed in: 6.2.3Fix
composer require shopware/platform:^6.2.3