Blind SQL-injection in DAL aggregations in Shopware
CVE-2024-22406
What is CVE-2024-22406?
The Shopware application API's search functionality poses a risk of SQL injection through its aggregations object. Specifically, the 'name' field in the aggregations object can be exploited via time-based SQL queries, potentially compromising the integrity of the database and exposing sensitive information. This vulnerability affects multiple Shopware versions and users are strongly advised to update to Shopware 6.5.7.4 or apply corresponding security measures via plugins for older versions. Keeping your systems updated is essential for maintaining security and protecting your e-commerce operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
shopware < 6.5.7.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
