CVE-2022-21652
- EPSS 0.3%
- Veröffentlicht 05.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:09
Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to th...
CVE-2022-21651
- EPSS 0.26%
- Veröffentlicht 05.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:09
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There...
CVE-2021-41188
- EPSS 0.51%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:25:43
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following confi...
CVE-2021-37711
- EPSS 0.52%
- Veröffentlicht 16.08.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:46
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also av...
CVE-2021-37710
- EPSS 0.36%
- Veröffentlicht 16.08.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability via SVG media files. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding securit...
CVE-2021-37709
- EPSS 0.22%
- Veröffentlicht 16.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log files of the Import/Export feature. Version 6.4.3.1 contains a patch. As workarounds for older versi...
CVE-2021-37708
- EPSS 5.91%
- Veröffentlicht 16.08.2021 20:15:48
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding securit...
CVE-2021-37707
- EPSS 0.22%
- Veröffentlicht 16.08.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:15:45
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, correspond...
CVE-2021-32717
- EPSS 0.33%
- Veröffentlicht 24.06.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:35
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibi...
CVE-2021-32716
- EPSS 0.31%
- Veröffentlicht 24.06.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:35
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can ...