PT-2023-18676 · Shopware · Shopware
Shyim
·
Published
2023-01-17
·
Updated
2023-01-25
·
CVE-2023-22734
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 6.4.18.1
Description
The newsletter double opt-in validation was not checked properly, allowing the complete double opt-in process to be skipped. This could result in inconsistencies in the newsletter systems of operators.
Recommendations
For versions 6.1, 6.2, and 6.3, consider installing a security plugin to mitigate the issue.
For all affected versions, upgrading to version 6.4.18.1 or later is recommended.
As a temporary workaround, consider disabling newsletter registration completely until a patch is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopware