QID 980377
QID 980377: Python (pip) Security Update for shuup (GHSA-663j-rjcr-789f)
Shuup application in versions 0.4.2 to 2.10.8 is affected by the Formula Injection vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-663j-rjcr-789f for updates pertaining to this vulnerability.
Vendor References
- GHSA-663j-rjcr-789f -
github.com/advisories/GHSA-663j-rjcr-789f
CVEs related to QID 980377
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-663j-rjcr-789f | shuup |
|