Логотип exploitDog
bind:CVE-2022-24872
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24872

Количество 2

Количество 2

nvd логотип

CVE-2022-24872

почти 4 года назад

Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-9wrv-g75h-8ccc

почти 4 года назад

Improper Access Control in Shopware

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24872

Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-9wrv-g75h-8ccc

Improper Access Control in Shopware

CVSS3: 8.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу