SB2020112321 - Multiple vulnerabilities in Shopware
Published: November 23, 2020 Updated: May 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 12 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Customer, Newsletter and Shopping Worlds modules. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
2) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the customer module when handling customer-supplied input. A remote user can submit specially crafted input to execute arbitrary script in a user's browser.
3) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the newsletter module when handling newsletter content. A remote attacker can inject a persistent script payload to execute arbitrary script code in a user's browser.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in shopping worlds when rendering stored content. A remote user can inject a specially crafted script payload to execute arbitrary script code in a user's browser.
5) Cross-site scripting (CVE-ID: CVE-2021-41188)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in the administration interface.
The vulnerability exists due to cross-site scripting in the administration interface when rendering crafted stored content. A remote user can inject a specially crafted payload to execute arbitrary script code in the administration interface.
6) Insufficient Session Expiration (CVE-ID: CVE-2022-21652)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to maintain access to an account after a password change.
The vulnerability exists due to improper session expiration in session handling when a password is changed. A remote user can continue using an existing session to maintain access to an account after a password change.
7) Input validation error (CVE-ID: CVE-2022-21651)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker to redirect users to an arbitrary URL.
The vulnerability exists due to improper input validation in URL handling when processing certain URLs. A remote attacker can supply a specially crafted URL to redirect users to an arbitrary URL.
8) Cross-site scripting (CVE-ID: CVE-2022-31057)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the administration interface when processing stored user-supplied content. A remote user can inject a malicious script to execute arbitrary script code in a user's browser.
9) Cross-site scripting (CVE-ID: CVE-2022-31148)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the customer module when processing stored customer-supplied input. A remote attacker can submit specially crafted input to execute arbitrary script code in a victim's browser.
10) Improper access control (CVE-ID: CVE-2022-36102)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to bypass access controls.
The vulnerability exists due to improper access control in backend admin controllers when using a certain URL notation. A remote user can call backend admin controllers with crafted URLs to bypass access controls.
11) Information disclosure (CVE-ID: CVE-2022-36101)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper exposure of sensitive information in the customer detail view in the backend administration when handling requests for customer details. A remote user can request the customer detail view to disclose sensitive information.
The exposed data includes hashed passwords and session IDs.
12) Improper Neutralization of Special Elements Used in a Template Engine (CVE-ID: CVE-2023-2017)
CWE-ID: CWE-1336 - Improper Neutralization of Special Elements Used in a Template Engine
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig rendered views when processing crafted PHP closures passed as strings or arrays. A remote user can supply crafted PHP closures that bypass the allow list to execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://snyk.io/vuln/SNYK-PHP-SHOPWARESHOPWARE-1040421
- https://github.com/shopware/shopware/commit/00a172e762c45af14cb16345a944a9e22ec12aeb
- https://github.com/shopware/shopware/commit/2351372e8d78a504f9dba20e42341509137e680b
- https://github.com/shopware/shopware/commit/13e67baae3adc6c3e231c323104fa66b4f7d2e93
- https://github.com/shopware5/shopware/security/advisories/GHSA-6gv9-7q4g-pmvm
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-11-2020
- https://github.com/shopware5/shopware/security/advisories/GHSA-hrfh-fp4x-crrq
- https://github.com/shopware5/shopware/security/advisories/GHSA-28fw-88hq-6jmm
- https://github.com/shopware5/shopware/security/advisories/GHSA-4p3x-8qw9-24w9
- https://docs.shopware.com/en/shopware-5-en/sicherheitsupdates/security-update-10-2021
- https://github.com/shopware/shopware/security/advisories/GHSA-4p3x-8qw9-24w9
- https://github.com/shopware5/shopware/security/advisories/GHSA-p523-jrph-qjc6
- https://docs.shopware.com/en/shopware-5-en/securityupdates/security-update-01-2022
- https://github.com/shopware/shopware/security/advisories/GHSA-p523-jrph-qjc6
- https://github.com/shopware5/shopware/security/advisories/GHSA-c53v-qmrx-93hg
- https://github.com/shopware/shopware/security/advisories/GHSA-c53v-qmrx-93hg
- https://github.com/shopware5/shopware/security/advisories/GHSA-q754-vwc4-p6qj
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2022
- https://github.com/shopware/shopware/security/advisories/GHSA-q754-vwc4-p6qj
- https://github.com/shopware5/shopware/security/advisories/GHSA-5834-xv5q-cgfw
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-07-2022
- https://github.com/shopware/shopware/security/advisories/GHSA-5834-xv5q-cgfw
- https://github.com/shopware5/shopware/security/advisories/GHSA-qc43-pgwq-3q2q
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-09-2022
- https://github.com/shopware/shopware/security/advisories/GHSA-qc43-pgwq-3q2q
- https://github.com/shopware5/shopware/security/advisories/GHSA-6vfq-jmxg-g58r
- https://github.com/shopware/shopware/security/advisories/GHSA-6vfq-jmxg-g58r
- https://github.com/shopware/shopware/security/advisories/GHSA-7v2v-9rm4-7m8f
- https://github.com/advisories/GHSA-7v2v-9rm4-7m8f