SB2021041243 - Multiple vulnerabilities in Shopware
Published: April 12, 2021 Updated: May 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to manipulate the order payment process.
The vulnerability exists due to improper access control in the order payment process when handling payment-related requests after an order is placed. A remote user can send a crafted request to manipulate the order payment process.
2) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in web root file exposure when serving requests with the project root configured as the web root instead of /public. A remote attacker can request sensitive files such as .env to disclose sensitive information.
Exposure occurs only when the project root is configured as the web root instead of /public.
3) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Store-API aggregations when handling Store-API aggregation requests. A remote attacker can send crafted aggregation requests to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://github.com/shopware/shopware/security/advisories/GHSA-88rc-3p98-rgvx
- https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2021
- https://github.com/shopware/shopware/security/advisories/GHSA-3pcr-4982-548m
- https://github.com/shopware/shopware/security/advisories/GHSA-qg7c-q3vq-rgxr