Account Enumeration Vulnerability in Shopware 6 by Shopware
CVE-2025-30150

5.5MEDIUM

Key Information:

Vendor

Shopware

Status
Vendor
CVE Published:
8 April 2025

What is CVE-2025-30150?

Shopware 6, a widely used commerce platform, is susceptible to an account enumeration vulnerability through its store-api. Attackers can exploit the endpoint /store-api/account/recovery-password to ascertain whether a specific email address is registered with an account. The response differentiates based on account existence: a clear indication of no account exists for the former, while returning a success message if an account is indeed found. This creates a potential risk for user data exposure. Users are strongly encouraged to upgrade to the latest versions, Shopware 6.6.10.3 or 6.5.8.17, to mitigate this risk. For those on the older version 6.4, corresponding security measures are available through a dedicated plugin.

Affected Version(s)

shopware < 6.5.8.17 < 6.5.8.17

shopware >= 6.6.0.0, < 6.6.10.3 < 6.6.0.0, 6.6.10.3

shopware >= 6.7.0.0-rc1, < 6.7.0.0-rc2 < 6.7.0.0-rc1, 6.7.0.0-rc2

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.