CVE-2022-31057 MEDIUM

CVE-2022-31057: Authenticated Stored XSS in Shopware Administration

Vendor Shopware
Product shopware
Weakness CWE-79 · XSS
Published June 27, 2022
Last update April 23, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

June 27, 2022 CVE published
April 23, 2025 Record updated