7.5

CVE-2023-22734

Improper Input Newsletter subscription option validation in shopware

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their newsletter systems. This problem has been fixed with version 6.4.18.1. Users are advised to upgrade. Users unable to upgrade may find security measures are available via a plugin for major versions 6.1, 6.2, and 6.3. Users may also disable newsletter registration completely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ShopwareShopware Version < 6.4.18.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.441
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
Patch
Vendor Advisory
https://github.com/shopware/platform/commit/f5a95ee2bcf1e546878450963ef1d9886e59a620
Patch
Third Party Advisory
https://github.com/shopware/platform/security/advisories/GHSA-46h7-vj7x-fxg2
Third Party Advisory