CVE-2022-24745
- EPSS 0.51%
- Veröffentlicht 09.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for gues...
CVE-2022-24747
- EPSS 1.06%
- Veröffentlicht 09.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and c...
CVE-2022-24748
- EPSS 0.73%
- Veröffentlicht 09.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper...
CVE-2022-24744
- EPSS 0.47%
- Veröffentlicht 09.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:00
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6...
CVE-2022-21652
- EPSS 0.79%
- Veröffentlicht 05.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:09
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to th...
CVE-2022-21651
- EPSS 0.77%
- Veröffentlicht 05.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:09
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There...
CVE-2021-41188
- EPSS 0.74%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:25:43
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following confi...
CVE-2021-37711
- EPSS 1.06%
- Veröffentlicht 16.08.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:46
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also av...
CVE-2021-37710
- EPSS 0.74%
- Veröffentlicht 16.08.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding securit...
CVE-2021-37709
- EPSS 0.77%
- Veröffentlicht 16.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versi...