Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6w9-r443-r752

Опубликовано: 08 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

Shopware vulnerable to blind SQL-injection in DAL aggregations

Impact

The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-injection and can be exploited using SQL parameters.

Patches

Update to Shopware 6.6.5.1 or 6.5.8.13

Workarounds

For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Credit

LogicalTrust

Пакеты

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

<= 6.5.8.12

6.5.8.13

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

<= 6.5.8.12

6.5.8.13

Наименование

shopware/platform

composer
Затронутые версииВерсия исправления

>= 6.6.0.0, <= 6.6.5.0

6.6.5.1

Наименование

shopware/core

composer
Затронутые версииВерсия исправления

>= 6.6.0.0, <= 6.6.5.0

6.6.5.1

EPSS

Процентиль: 72%
0.00704
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.3
nvd
больше 1 года назад

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the `aggregations` object. The `name` field in this `aggregations` object is vulnerable SQL-injection and can be exploited using SQL parameters. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.1, 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.

EPSS

Процентиль: 72%
0.00704
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-89