PT-2022-23192 · Shopware · Shopware

Published

2022-09-12

·

Updated

2023-07-21

·

CVE-2022-36101

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 5.7.15
Description The request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. There are no known workarounds for this issue.
Recommendations For versions prior to 5.7.15, update to version 5.7.15 via the Auto-Updater or directly via the download overview. For older versions, consider using the Security Plugin as a mitigation measure until the update to 5.7.15 can be applied.

Exploit

Fix

Information Disclosure

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-36101
GHSA-6VFQ-JMXG-G58R

Affected Products

Shopware