PT-2023-18676 · Shopware · Shopware

Shyim

·

Publicado

2023-01-17

·

Atualizado

2023-01-25

·

CVE-2023-22734

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.18.1
Description The newsletter double opt-in validation was not checked properly, allowing the complete double opt-in process to be skipped. This could result in inconsistencies in the newsletter systems of operators.
Recommendations For versions 6.1, 6.2, and 6.3, consider installing a security plugin to mitigate the issue. For all affected versions, upgrading to version 6.4.18.1 or later is recommended. As a temporary workaround, consider disabling newsletter registration completely until a patch is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22734
GHSA-46H7-VJ7X-FXG2

Produtos afetados

Shopware