PT-2023-18675 · Shopware · Shopware

Shyim

·

Published

2023-01-17

·

Updated

2023-01-25

·

CVE-2023-22733

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.18.1
Description The log module in Shopware writes out all kinds of sent mails, potentially allowing an attacker with access to local system logs or a centralized logging store to access other users' accounts. This issue can be exploited to gain access to password reset emails of customers and admin users, potentially leading to further unauthorized access.
Recommendations For versions 6.1, 6.2, and 6.3, install the corresponding security plugin to address the issue. For all affected versions, remove the log module ACL rights from all users as a temporary workaround. Disable logging until the issue is fully resolved. Update to version 6.4.18.1 or later for the full range of functions and to fully address the issue.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2023-22733
GHSA-7CP7-JFP6-JH4F

Affected Products

Shopware