Improper Output Neutralization for Logs in Shopware - CVE-2023-22733

 

Improper Output Neutralization for Logs in Shopware - CVE-2023-22733

Published: January 17, 2023 / Updated: May 19, 2026


Vulnerability identifier: #VU131887
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22733
CWE-ID: CWE-117
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper output neutralization for logs in the log module when viewing logged sent mails. A remote user can access password reset emails to disclose sensitive information.

The issue can expose password reset emails for both customers and administrative users.


Affected software

Shopware

How to mitigate CVE-2023-22733

Install security update from vendor's website.

Shopware - update to 6.4.18.1

External References

Related Security Bulletins