CVE-2022-36101
- EPSS 0.47%
- Veröffentlicht 12.09.2022 20:15:12
- Zuletzt bearbeitet 21.11.2024 07:12:23
Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in...
CVE-2022-31148
- EPSS 0.69%
- Veröffentlicht 01.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:59
Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 ...
CVE-2022-31057
- EPSS 0.41%
- Veröffentlicht 27.06.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:48
Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-24892
- EPSS 0.29%
- Veröffentlicht 28.04.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:51:20
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker ...
CVE-2022-24879
- EPSS 0.14%
- Veröffentlicht 28.04.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:18
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validat...
CVE-2022-24873
- EPSS 0.66%
- Veröffentlicht 28.04.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:17
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vu...
CVE-2022-24872
- EPSS 0.19%
- Veröffentlicht 20.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:17
Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versio...
CVE-2022-24871
- EPSS 0.35%
- Veröffentlicht 20.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:17
Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6....
CVE-2022-24748
- EPSS 0.22%
- Veröffentlicht 09.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper...
CVE-2022-24747
- EPSS 0.33%
- Veröffentlicht 09.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and c...