Miggo Logo

CVE-2022-31148: Shopware vulnerable to persistent cross site scripting (XSS) in customer module

5.4

CVSS Score
3.1

Basic Information

EPSS Score
0.71577%
Published
7/27/2022
Updated
1/31/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
shopware/shopwarecomposer>= 5.7.0, <= 5.7.135.7.14

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t P*rsist*nt XSS in *ustom*r mo*ul* ### P*t***s W* r**omm*n* up**tin* to t** *urr*nt v*rsion *.*.**. You **n **t t** up**t* to *.*.** r**ul*rly vi* t** *uto-Up**t*r or *ir**tly vi* t** *ownlo** ov*rvi*w. *or ol**r v*rsions you **n us* t**

Reasoning

No *n*lysis *v*il**l*