Description
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1610 | Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9. |
Github GHSA |
GHSA-3qrq-r688-vvh4 | Multiple valid tokens for password reset in Shopware |
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:31:35.369Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24892
Updated: 2024-08-03T04:29:00.669Z
Status : Modified
Published: 2022-04-28T15:15:10.027
Modified: 2024-11-21T06:51:20.243
Link: CVE-2022-24892
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA