Incorrect authorization in Shopware - #VU145370
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose unapproved product review information.
The vulnerability exists due to incorrect authorization in nested store-api associations when handling store api requests for product review data. A remote attacker can access review content, rating, and display name fields to disclose unapproved product review information.
The issue exposes reviews that are awaiting moderation and have not been approved for publication.