Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0414 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin.
Github GHSA Github GHSA GHSA-8r6h-m72v-38fg Shopware vulnerable to Improper Input Validation of Clearance sale in cart
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:22:13.869Z

Reserved: 2023-01-06T14:21:05.891Z

Link: CVE-2023-22730

cve-icon Vulnrichment

Updated: 2024-08-02T10:13:50.235Z

cve-icon NVD

Status : Modified

Published: 2023-01-17T22:15:10.867

Modified: 2024-11-21T07:45:18.660

Link: CVE-2023-22730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.