SB2021041243 - Multiple vulnerabilities in Shopware



SB2021041243 - Multiple vulnerabilities in Shopware

Published: April 12, 2021 Updated: May 20, 2026

Security Bulletin ID SB2021041243
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to manipulate the order payment process.

The vulnerability exists due to improper access control in the order payment process when handling payment-related requests after an order is placed. A remote user can send a crafted request to manipulate the order payment process.


2) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in web root file exposure when serving requests with the project root configured as the web root instead of /public. A remote attacker can request sensitive files such as .env to disclose sensitive information.

Exposure occurs only when the project root is configured as the web root instead of /public.


3) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in Store-API aggregations when handling Store-API aggregation requests. A remote attacker can send crafted aggregation requests to disclose sensitive information.


Remediation

Install update from vendor's website.