shuup
E-Commerce Platform
Activity
- Latest release
- 5y ago
- Total releases
- 146
- Cadence
- ~3 days
- Last 12 months
- 0
Details
- License
- custom
- First release
- Jun 04, 2018
| Version | Released | |
|---|---|---|
2.14.3
patch
|
2.14.3
patch
Dependencies (31)
+ 23 more |
|
3.1.0
minor
|
3.1.0
minor
Dependencies (32)
+ 24 more |
|
3.0.0
major
|
3.0.0
major
Dependencies (32)
+ 24 more |
|
3.0.0b3
pre
|
3.0.0b3
pre
Dependencies (32)
+ 24 more |
|
3.0.0b2
pre
|
3.0.0b2
pre
Dependencies (31)
+ 23 more |
|
2.14.2
patch
|
2.14.2
patch
Dependencies (31)
+ 23 more |
|
3.0.0b1
pre
|
3.0.0b1
pre
Dependencies (31)
+ 23 more |
|
2.14.1
patch
|
2.14.1
patch
Dependencies (31)
+ 23 more |
|
2.14.0
minor
|
2.14.0
minor
Dependencies (31)
+ 23 more |
|
2.13.0
minor
|
2.13.0
minor
Dependencies (31)
+ 23 more |
|
2.12.0
minor
|
2.12.0
minor
Dependencies (31)
+ 23 more |
|
2.11.0
minor
|
2.11.0
minor
Dependencies (31)
+ 23 more |
|
2.10.8
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.8
patch
Dependencies (31)
+ 23 more |
|
2.10.7
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.7
patch
Dependencies (31)
+ 23 more |
|
2.10.6
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.6
patch
Dependencies (31)
+ 23 more |
|
2.10.5
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.5
patch
Dependencies (31)
+ 23 more |
|
2.10.4
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.4
patch
Dependencies (31)
+ 23 more |
|
2.10.3
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.3
patch
Dependencies (31)
+ 23 more |
|
2.10.2
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.2
patch
Dependencies (31)
+ 23 more |
|
2.10.1
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.1
patch
Dependencies (31)
+ 23 more |
|
2.10.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.0
minor
Dependencies (31)
+ 23 more |
|
2.10.0b1
pre
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.10.0b1
pre
Dependencies (31)
+ 23 more |
|
2.9.2
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.9.2
patch
Dependencies (31)
+ 23 more |
|
2.9.1
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.9.1
patch
Dependencies (31)
+ 23 more |
|
2.9.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.9.0
minor
Dependencies (31)
+ 23 more |
|
2.8.3
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.8.3
patch
Dependencies (31)
+ 23 more |
|
2.8.1
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.8.1
patch
Dependencies (31)
+ 23 more |
|
2.8.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.8.0
minor
Dependencies (31)
+ 23 more |
|
2.7.3
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.7.3
patch
Dependencies (31)
+ 23 more |
|
2.7.2
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.7.2
patch
Dependencies (31)
+ 23 more |
|
2.7.1
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.7.1
patch
Dependencies (31)
+ 23 more |
|
2.7.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.7.0
minor
Dependencies (31)
+ 23 more |
|
2.6.5
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.6.5
patch
Dependencies (31)
+ 23 more |
|
2.6.4
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.6.4
patch
Dependencies (47)
+ 39 more |
|
2.6.3
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.6.3
patch
Dependencies (47)
+ 39 more |
|
2.6.2
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.6.2
patch
Dependencies (47)
+ 39 more |
|
2.6.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.6.0
minor
Dependencies (47)
+ 39 more |
|
2.5.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.5.0
minor
Dependencies (48)
+ 40 more |
|
2.4.0
minor
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.4.0
minor
Dependencies (48)
+ 40 more |
|
2.3.18
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.18
patch
Dependencies (48)
+ 40 more |
|
2.3.17
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.17
patch
Dependencies (48)
+ 40 more |
|
2.3.16
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.16
patch
Dependencies (48)
+ 40 more |
|
2.3.15
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.15
patch
Dependencies (48)
+ 40 more |
|
2.3.14
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.14
patch
Dependencies (47)
+ 39 more |
|
2.3.13
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.13
patch
Dependencies (47)
+ 39 more |
|
2.3.12
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.12
patch
Dependencies (47)
+ 39 more |
|
2.3.11
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.11
patch
Dependencies (47)
+ 39 more |
|
2.3.10
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.10
patch
Dependencies (47)
+ 39 more |
|
2.3.9
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.9
patch
Dependencies (47)
+ 39 more |
|
2.3.8
patch
2 CVEs
CVE-2021-25963
GHSA-5pcx-vqjp-p34w
PYSEC-2021-350
Oct 04, 2021
Cross-site Scripting in shuup
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev
CVE-2021-25962
GHSA-663j-rjcr-789f
PYSEC-2021-355
Sep 30, 2021
CSV injection in shuup
8.0
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
High
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed. Affected versions
1.10.0
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.2
1.10.3
1.10.4
+ 122 more Show less
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.11.0
1.11.1
1.11.10
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.6.0
1.6.15
1.6.16
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.3
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.10
1.9.11
1.9.12
1.9.13
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.1
2.1.10
2.1.11
2.1.12
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.10.0
2.10.0b1
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.18
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.5.0
2.6.0
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.8.0
2.8.1
2.8.3
2.9.0
2.9.1
2.9.2
Fixed in
2.11.0
References
Updated Oct 23, 2024 · Source: OSV.dev |
2.3.8
patch
Dependencies (47)
+ 39 more |