Логотип exploitDog
bind:CVE-2022-36102
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-36102

Количество 2

Количество 2

nvd логотип

CVE-2022-36102

больше 3 лет назад

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current version (5.7.15). Users can get the update via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-qc43-pgwq-3q2q

больше 3 лет назад

Shopware access control list bypassed via crafted specific URLs

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-36102

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current version (5.7.15). Users can get the update via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qc43-pgwq-3q2q

Shopware access control list bypassed via crafted specific URLs

CVSS3: 6.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу