PT-2023-18676 · Shopware · Shopware

Shyim

·

Published

2023-01-17

·

Updated

2023-01-25

·

CVE-2023-22734

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 6.4.18.1
Description The newsletter double opt-in validation was not checked properly, allowing the complete double opt-in process to be skipped. This could result in inconsistencies in the newsletter systems of operators.
Recommendations For versions 6.1, 6.2, and 6.3, consider installing a security plugin to mitigate the issue. For all affected versions, upgrading to version 6.4.18.1 or later is recommended. As a temporary workaround, consider disabling newsletter registration completely until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-22734
GHSA-46H7-VJ7X-FXG2

Affected Products

Shopware