Vulnerability identifier: #VU77753
Vulnerability risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-754
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Shopware
Web applications /
E-Commerce systems
Vendor: Shopware
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper mail validation in the registration process. A remote attacker can construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Shopware: 5.0.0-WORKSHOP - 5.7.17
External links
https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2023
https://github.com/shopware5/shopware/commit/39cc714d9a0be33b43877044d0b88ea3c6b43f3d
https://github.com/shopware/shopware/security/advisories/GHSA-gh66-fp7j-98v5
https://www.shopware.com/en/changelog-sw5/#5-7-18
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.