PT-2023-18676 · Shopware · Shopware
Shyim
·
Publicado
2023-01-17
·
Atualizado
2023-01-25
·
CVE-2023-22734
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.4.18.1
Description
The newsletter double opt-in validation was not checked properly, allowing the complete double opt-in process to be skipped. This could result in inconsistencies in the newsletter systems of operators.
Recommendations
For versions 6.1, 6.2, and 6.3, consider installing a security plugin to mitigate the issue.
For all affected versions, upgrading to version 6.4.18.1 or later is recommended.
As a temporary workaround, consider disabling newsletter registration completely until a patch is applied.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Shopware