Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are advised to update and may get the update either via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6722 | Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are advised to update and may get the update either via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue. |
Github GHSA |
GHSA-6vfq-jmxg-g58r | Shopware contains sensitive data in backend customer module |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T17:12:13.936Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-36101
Updated: 2024-08-03T09:52:00.539Z
Status : Modified
Published: 2022-09-12T20:15:12.803
Modified: 2024-11-21T07:12:23.440
Link: CVE-2022-36101
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA