Blind SQL-injection in DAL aggregations in Shopware
CVE-2024-22406

9.3CRITICAL

Key Information:

Vendor

Shopware

Status
Vendor
CVE Published:
16 January 2024

What is CVE-2024-22406?

The Shopware application API's search functionality poses a risk of SQL injection through its aggregations object. Specifically, the 'name' field in the aggregations object can be exploited via time-based SQL queries, potentially compromising the integrity of the database and exposing sensitive information. This vulnerability affects multiple Shopware versions and users are strongly advised to update to Shopware 6.5.7.4 or apply corresponding security measures via plugins for older versions. Keeping your systems updated is essential for maintaining security and protecting your e-commerce operations.

Affected Version(s)

shopware < 6.5.7.4

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.