Shopware

Shopware

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.14%
  • Veröffentlicht 17.04.2023 11:15:42
  • Zuletzt bearbeitet 21.11.2024 07:57:46

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox ex...

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have incon...

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may...

  • EPSS 0.41%
  • Veröffentlicht 17.01.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4....

  • EPSS 5.21%
  • Veröffentlicht 17.01.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template...

  • EPSS 0.3%
  • Veröffentlicht 17.01.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:45:18

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and ...

  • EPSS 0.61%
  • Veröffentlicht 12.09.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:12:23

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to...

  • EPSS 0.47%
  • Veröffentlicht 12.09.2022 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:12:23

Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in...

  • EPSS 0.69%
  • Veröffentlicht 01.08.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:59

Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 ...

  • EPSS 0.41%
  • Veröffentlicht 27.06.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:48

Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.