Account Enumeration Vulnerability in Shopware 6 by Shopware
CVE-2025-30150
What is CVE-2025-30150?
Shopware 6, a widely used commerce platform, is susceptible to an account enumeration vulnerability through its store-api. Attackers can exploit the endpoint /store-api/account/recovery-password to ascertain whether a specific email address is registered with an account. The response differentiates based on account existence: a clear indication of no account exists for the former, while returning a success message if an account is indeed found. This creates a potential risk for user data exposure. Users are strongly encouraged to upgrade to the latest versions, Shopware 6.6.10.3 or 6.5.8.17, to mitigate this risk. For those on the older version 6.4, corresponding security measures are available through a dedicated plugin.
Affected Version(s)
shopware < 6.5.8.17 < 6.5.8.17
shopware >= 6.6.0.0, < 6.6.10.3 < 6.6.0.0, 6.6.10.3
shopware >= 6.7.0.0-rc1, < 6.7.0.0-rc2 < 6.7.0.0-rc1, 6.7.0.0-rc2