PT-2022-16963 · Shopware · Shopware

Published

2022-04-28

·

Updated

2022-05-10

·

CVE-2022-24892

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Shopware versions 5.0.4 through 5.7.8
Description The issue allows an attacker to take over a victim's account if they gain access to the victim's email account and find an unused password reset token in the emails. This is possible because multiple tokens for password reset can be requested, and all tokens can be used to change the password.
Recommendations For versions 5.0.4 through 5.7.8, update to version 5.7.9 to resolve the issue. As a temporary workaround, consider restricting access to password reset functionality until the update is applied. For older versions, consider using the Security Plugin as an alternative mitigation measure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24892
GHSA-3QRQ-R688-VVH4

Affected Products

Shopware