PT-2022-16963 · Shopware · Shopware
Published
2022-04-28
·
Updated
2022-05-10
·
CVE-2022-24892
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shopware versions 5.0.4 through 5.7.8
Description
The issue allows an attacker to take over a victim's account if they gain access to the victim's email account and find an unused password reset token in the emails. This is possible because multiple tokens for password reset can be requested, and all tokens can be used to change the password.
Recommendations
For versions 5.0.4 through 5.7.8, update to version 5.7.9 to resolve the issue.
As a temporary workaround, consider restricting access to password reset functionality until the update is applied.
For older versions, consider using the Security Plugin as an alternative mitigation measure.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware