Vulnerability Description
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shuup | Shuup | >= 1.6.0, <= 2.10.8 |
Related Weaknesses (CWE)
References
- https://github.com/shuup/shuup/commit/75714c37e32796eb7cbb0d977af5bcaa26573588PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25963Third Party Advisory
- https://github.com/shuup/shuup/commit/75714c37e32796eb7cbb0d977af5bcaa26573588PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25963Third Party Advisory
FAQ
What is CVE-2021-25963?
CVE-2021-25963 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to ...
How severe is CVE-2021-25963?
CVE-2021-25963 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25963?
Check the references section above for vendor advisories and patch information. Affected products include: Shuup Shuup.