peter bassill · operator
$ cve CVE-2017-15374 JSON

CVE-2017-15374 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent execution in the customer and orders section of the backend. The execution occurs in the administrator backend listing when processing a preview of the customers (kunden) or orders (bestellungen). The injection can be performed interactively via user registration or by manipulation of the order information inputs. The issue can be exploited by low privileged user accounts against higher privileged (admin or moderator) accounts.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS4.81% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2017-10-16
Last modified2026-06-17

Affected (1)

VendorProduct
shopwareshopware

Public exploits

SourceTitleDate
exploit-dbShopware 5.2.5/5.3 - Cross-Site Scripting2018-01-21

References

→ the Explorer  ·  watch your stack  ·  NVD