Improper access control in Shopware - CVE-2024-42354
Published: August 8, 2024 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in store-api criteria processing for ManyToMany associations when handling requests involving extension-defined entities. A remote attacker can send a specially crafted request to disclose sensitive information.
This issue cannot be reproduced with the default entities and can be triggered with extensions. User interaction is required.