#VU77753 Improper Check for Unusual or Exceptional Conditions in Shopware - CVE-2023-34099


Vulnerability identifier: #VU77753

Vulnerability risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-34099

CWE-ID: CWE-754

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Shopware
Web applications / E-Commerce systems

Vendor: Shopware

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper mail validation in the registration process. A remote attacker can construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Shopware: 5.0.0-WORKSHOP - 5.7.17


External links
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023
https://github.com/shopware5/shopware/commit/39cc714d9a0be33b43877044d0b88ea3c6b43f3d
https://github.com/shopware/shopware/security/advisories/GHSA-gh66-fp7j-98v5
https://www.shopware.com/en/changelog-sw5/#5-7-18


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability