Blind SQL-injection in DAL aggregations in Shopware
CVE-2024-22406
9.3CRITICAL
What is CVE-2024-22406?
The Shopware application API's search functionality poses a risk of SQL injection through its aggregations object. Specifically, the 'name' field in the aggregations object can be exploited via time-based SQL queries, potentially compromising the integrity of the database and exposing sensitive information. This vulnerability affects multiple Shopware versions and users are strongly advised to update to Shopware 6.5.7.4 or apply corresponding security measures via plugins for older versions. Keeping your systems updated is essential for maintaining security and protecting your e-commerce operations.
Affected Version(s)
shopware < 6.5.7.4