Skip to content

Authenticated Stored XSS in Administration

Moderate
mitelg published GHSA-4p3x-8qw9-24w9 Oct 26, 2021

Package

composer shopware/shopware (Composer)

Affected versions

<=5.7.5

Patched versions

5.7.6

Description

Impact

Authenticated Stored XSS in Administration

Patches

Use the Security Plugin:
https://store.shopware.com/en/swag575294366635f/shopware-security-plugin.html

Workarounds

If you cannot use the security plugin, add the following config to your .htaccess file

<IfModule mod_headers.c>
    <FilesMatch "\.(?i:svg)$">
        Header set Content-Security-Policy "script-src 'none'"
    </FilesMatch>
</IfModule>

If you are using nginx as server config, you can add the following to your configuration:

server {
    # ...

    location ~* ^.+\.svg$ {
        add_header Content-Security-Policy "script-src 'none'";
    }
}

References

https://docs.shopware.com/en/shopware-5-en/sicherheitsupdates/security-update-10-2021

Severity

Moderate

CVE ID

CVE-2021-41188

Weaknesses

No CWEs