PT-2023-18672 · Shopware · Shopware
Aragon999
+1
·
Published
2023-01-17
·
Updated
2023-01-25
·
CVE-2023-22730
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.4.18.1
Description
The issue allows users to bypass quantity limits in sales by adding the same line item multiple times to the cart using the API. The Cart Validators checked the line item's individuality, which could be exploited. This problem has been fixed with version 6.4.18.1.
Recommendations
For versions 6.1, 6.2, and 6.3, obtain the fix via a plugin.
Update to version 6.4.18.1 or later to resolve the issue.
As a temporary workaround, consider disabling the newsletter registration or restricting access to the cart API to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware