CVE-2019-12935
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.4epss 2.7%
exploitation probability
2.7%top 15% of all CVEs
observed exploitation
nono source reports it
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:C/UI:R
Affected products
n/a · n/a