PT-2022-16951 · Shopware · Shopware

Published

2022-04-28

·

Updated

2022-05-07

·

CVE-2022-24879

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 5.7.9
Description The issue concerns a malfunction in cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This could allow an attacker to impersonate a victim if the attacker is able to use the same device as the victim used beforehand.
Recommendations For versions prior to 5.7.9, update to version 5.7.9 to resolve the issue. As a temporary workaround for older versions, consider using the Shopware security plugin to mitigate the vulnerability.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24879
GHSA-PF38-V6QJ-J23H

Affected Products

Shopware