Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1610 | Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9. |
Github GHSA |
GHSA-3qrq-r688-vvh4 | Multiple valid tokens for password reset in Shopware |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:31:35.369Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24892
Updated: 2024-08-03T04:29:00.669Z
Status : Modified
Published: 2022-04-28T15:15:10.027
Modified: 2024-11-21T06:51:20.243
Link: CVE-2022-24892
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA