Описание
Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been addressed in version 5.7.18 and users are advised to update. There are no known workarounds for this vulnerability.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Release Notes
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия от 5.1.4 (включая) до 5.7.17 (включая)
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00105
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-754
Связанные уязвимости
CVSS3: 5.3
github
больше 2 лет назад
Shopware improper mail validation vulnerability
EPSS
Процентиль: 29%
0.00105
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-754