Shopware

Shopware

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 27.06.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:32

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts...

  • EPSS 0.26%
  • Veröffentlicht 27.06.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:32

Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the spec...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 21.04.2023 14:15:07
  • Zuletzt bearbeitet 05.02.2025 15:15:16

Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 17.04.2023 11:15:42
  • Zuletzt bearbeitet 21.11.2024 07:57:46

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox ex...

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have incon...

  • EPSS 0.41%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4....

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may...

  • EPSS 5.21%
  • Veröffentlicht 17.01.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template...

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and ...

  • EPSS 0.61%
  • Veröffentlicht 12.09.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:12:23

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to...