CVE-2021-32713
Cross-site scripting
4.8
MEDIUM
CVSS 3.1
EPSS 0.39%
Description
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.
How to fix CVE-2021-32713
To remediate CVE-2021-32713, upgrade the affected package to a fixed version below.
- —upgrade to 5.6.10 or later
Is CVE-2021-32713 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.6.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |