SQL injection in Shopware - CVE-2024-42357
Published: August 8, 2024 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to sql injection in the DAL aggregations name field when processing search requests with aggregation parameters. A remote attacker can send specially crafted SQL parameters in the aggregations object to disclose sensitive information, modify data, or cause a denial of service.