Логотип exploitDog
bind:CVE-2023-22733
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22733

Количество 2

Количество 2

nvd логотип

CVE-2023-22733

около 3 лет назад

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users accounts. This issue has been addressed in version 6.4.18.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. Users unable to upgrade may remove from all users the log module ACL rights or disable logging.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-7cp7-jfp6-jh4f

около 3 лет назад

Shopware's log module vulnerable to Improper Output Neutralization

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-22733

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of sent mails. An attacker with access to either the local system logs or a centralized logging store may have access to other users accounts. This issue has been addressed in version 6.4.18.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. Users unable to upgrade may remove from all users the log module ACL rights or disable logging.

CVSS3: 2.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-7cp7-jfp6-jh4f

Shopware's log module vulnerable to Improper Output Neutralization

CVSS3: 2.7
0%
Низкий
около 3 лет назад

Уязвимостей на страницу