PT-2021-19874 · Shopware · Shopware

Lowshyim

·

Published

2021-06-24

·

Updated

2021-07-01

·

CVE-2021-32709

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.1.1
Description The issue concerns the creation of order credits not being validated by Access Control List (ACL) in admin orders. This could potentially allow unauthorized actions. It is recommended to update to the current version to address this issue. For older versions, security measures are available via a plugin.
Recommendations For versions 6.1, 6.2, and 6.3, install the corresponding security plugin to mitigate the risk. Update to version 6.4.1.1 to fully resolve the issue.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32709
GHSA-G7W8-PP9W-7P32
GHSA-P696-GF58-9W97

Affected Products

Shopware