Impact
Shopware, an open commerce platform, contains a flaw in the deepLinkCode handling of the store-api.order endpoint. The system performs an insufficient check on filter types for unauthenticated users, allowing them to retrieve order data belonging to other customers. This vulnerability can lead to unauthorized disclosure of order details, impacting confidentiality and potentially exposing sensitive customer information. The weakness is identified as CWE-863 (Improper Authorization).
Affected Systems
Relevant Shopware products affected are the core and platform components. Versions released prior to 6.7.8.1 and 6.6.10.15 are susceptible. No further version granularity is provided in the CVE data. Vendors have confirmed that upgrading to 6.7.8.1 or later, or to 6.6.10.15 or later, removes the vulnerability.
Risk and Exploitability
The CVSS v3 score of 8.9 classifies this issue as High severity. The EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit it remotely by sending unauthenticated requests to the store‑api.order endpoint; no special privileges or additional credentials are required.
OpenCVE Enrichment
Github GHSA