Improper Restriction of Excessive Authentication Attempts in Shopware - #VU145372
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of excessive authentication attempts in DocumentRoute guest authentication when handling guest document-download requests. A remote attacker can repeatedly guess the postal code for a valid document download link to disclose sensitive information.
Exploitation requires a valid document download link and knowledge of the recipient\'s email address.