VYPR
Medium severity6.1NVD Advisory· Published Aug 5, 2025· Updated Jun 17, 2026

CVE-2025-51541

CVE-2025-51541

Description

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to inject malicious JavaScript. This vulnerability can be exploited via a Cross-Site Request Forgery (CSRF) attack due to the absence of CSRF protections on the POST request. An unauthenticated remote attacker can craft a malicious web page that, when visited by a victim, stores the payload persistently in the installation configuration. As a result, the payload executes whenever any user subsequently accesses the vulnerable installation page, leading to persistent client-side code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Shopware/Shopware3 versions
    cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*range: >=6.1.0,<6.2.3
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.