PT-2021-21827 · Shopware · Shopware

Shyim

·

Published

2021-08-16

·

Updated

2022-04-25

·

CVE-2021-37709

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.3.1
Description The issue involves an insecure direct object reference of log files of the Import/Export feature. This allows unauthorized access to sensitive information. A patch for this issue is available in version 6.4.3.1. For older versions of 6.1, 6.2, and 6.3, security measures are available via a plugin.
Recommendations For versions prior to 6.4.3.1, update to version 6.4.3.1 to resolve the issue. For older versions of 6.1, 6.2, and 6.3, install the available security plugin as a workaround. As a temporary measure, consider restricting access to the Import/Export feature until the update or plugin installation is complete.

Fix

Insertion into Log File

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37709
GHSA-54GP-QFF8-946C

Affected Products

Shopware