CVE-2023-22734
Shopware is an open source commerce platform based on Symfony Framework and Vue js.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly, and it was possible to skip the complete double opt in process. As a result operators may have inconsistencies in their newsletter systems. This problem has been fixed with version 6.4.18.1. Users are advised to upgrade. Users unable to upgrade may find security measures are available via a plugin for major versions 6.1, 6.2, and 6.3. Users may also disable newsletter registration completely.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- shopware/shopware
- Source
- security-advisories@github.com
References
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updatesPatch, Vendor Advisory
- https://github.com/shopware/platform/commit/f5a95ee2bcf1e546878450963ef1d9886e59a620Patch, Third Party Advisory
- https://github.com/shopware/platform/security/advisories/GHSA-46h7-vj7x-fxg2Third Party Advisory
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updatesPatch, Vendor Advisory
- https://github.com/shopware/platform/commit/f5a95ee2bcf1e546878450963ef1d9886e59a620Patch, Third Party Advisory
- https://github.com/shopware/platform/security/advisories/GHSA-46h7-vj7x-fxg2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.