SB2020112321 - Multiple vulnerabilities in Shopware



SB2020112321 - Multiple vulnerabilities in Shopware

Published: November 23, 2020 Updated: May 19, 2026

Security Bulletin ID SB2020112321
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 12
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 25% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 12 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the Customer, Newsletter and Shopping Worlds modules. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


2) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary script in a user's browser.

The vulnerability exists due to cross-site scripting in the customer module when handling customer-supplied input. A remote user can submit specially crafted input to execute arbitrary script in a user's browser.


3) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary script code in a user's browser.

The vulnerability exists due to cross-site scripting in the newsletter module when handling newsletter content. A remote attacker can inject a persistent script payload to execute arbitrary script code in a user's browser.


4) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary script code in a user's browser.

The vulnerability exists due to cross-site scripting in shopping worlds when rendering stored content. A remote user can inject a specially crafted script payload to execute arbitrary script code in a user's browser.


5) Cross-site scripting (CVE-ID: CVE-2021-41188)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary script code in the administration interface.

The vulnerability exists due to cross-site scripting in the administration interface when rendering crafted stored content. A remote user can inject a specially crafted payload to execute arbitrary script code in the administration interface.


6) Insufficient Session Expiration (CVE-ID: CVE-2022-21652)

CWE-ID: CWE-613 - Insufficient Session Expiration

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to maintain access to an account after a password change.

The vulnerability exists due to improper session expiration in session handling when a password is changed. A remote user can continue using an existing session to maintain access to an account after a password change.


7) Input validation error (CVE-ID: CVE-2022-21651)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to redirect users to an arbitrary URL.

The vulnerability exists due to improper input validation in URL handling when processing certain URLs. A remote attacker can supply a specially crafted URL to redirect users to an arbitrary URL.


8) Cross-site scripting (CVE-ID: CVE-2022-31057)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary script code in a user's browser.

The vulnerability exists due to cross-site scripting in the administration interface when processing stored user-supplied content. A remote user can inject a malicious script to execute arbitrary script code in a user's browser.


9) Cross-site scripting (CVE-ID: CVE-2022-31148)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.

The vulnerability exists due to cross-site scripting in the customer module when processing stored customer-supplied input. A remote attacker can submit specially crafted input to execute arbitrary script code in a victim's browser.


10) Improper access control (CVE-ID: CVE-2022-36102)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to bypass access controls.

The vulnerability exists due to improper access control in backend admin controllers when using a certain URL notation. A remote user can call backend admin controllers with crafted URLs to bypass access controls.


11) Information disclosure (CVE-ID: CVE-2022-36101)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper exposure of sensitive information in the customer detail view in the backend administration when handling requests for customer details. A remote user can request the customer detail view to disclose sensitive information.

The exposed data includes hashed passwords and session IDs.


12) Improper Neutralization of Special Elements Used in a Template Engine (CVE-ID: CVE-2023-2017)

CWE-ID: CWE-1336 - Improper Neutralization of Special Elements Used in a Template Engine

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig rendered views when processing crafted PHP closures passed as strings or arrays. A remote user can supply crafted PHP closures that bypass the allow list to execute arbitrary code.


Remediation

Install update from vendor's website.

References