Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the “aggregations” object. The ‘name’ field in this “aggregations” object is vulnerable SQL-injection and can be exploited using time-based SQL-queries. This issue has been addressed and users are advised to update to Shopware 6.5.7.4. For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-01-16T22:30:04.324Z
Updated: 2024-08-01T22:43:34.927Z
Reserved: 2024-01-10T15:09:55.549Z
Link: CVE-2024-22406
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-16T23:15:08.233
Modified: 2024-11-21T08:56:13.207
Link: CVE-2024-22406
Redhat
No data.