PT-2022-16944 · Shopware · Shopware
Nils Evers
·
Published
2022-04-20
·
Updated
2022-05-03
·
CVE-2022-24872
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.4.10.1
Description
The issue concerns permissions set to sales channel context by admin-api, which remain usable within a normal user session. This affects Shopware, an open commerce platform based on Symfony Framework and Vue. There are no known workarounds for this issue.
Recommendations
For versions 6.1, 6.2, and 6.3, install the corresponding security plugin to address the issue.
For all affected versions, update to version 6.4.10.1 to resolve the issue. The update can be obtained regularly via the Auto-Updater or directly via the download overview.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware