Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r6h-m72v-38fg

Опубликовано: 17 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Shopware vulnerable to Improper Input Validation of Clearance sale in cart

Impact

It is possible to put the same line item multiple one in the cart using API, the Cart Validators checked the line item's individuality and the user was able to skip the clearance sale in cart

Patches

The problem has been fixed with 6.4.18.1

Workarounds

For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. Or disable the newsletter registration completely.

References

https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates

Пакеты

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.4.18.0

6.4.18.1

EPSS

Процентиль: 53%
0.00298
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin.

EPSS

Процентиль: 53%
0.00298
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-20