QID 980462
QID 980462: Python (pip) Security Update for shuup (GHSA-5pcx-vqjp-p34w)
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5pcx-vqjp-p34w for updates pertaining to this vulnerability.
Vendor References
- GHSA-5pcx-vqjp-p34w -
github.com/advisories/GHSA-5pcx-vqjp-p34w
CVEs related to QID 980462
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5pcx-vqjp-p34w | shuup |
|