CVE-2018-20713: SQL Injection
Published Jan 15, 2019
·Updated
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
Affected Software
2 affected componentsFixes available
composer/shopware/shopware<5.4.3
5.4.3
Shopware Shopware<5.4.3
Event History
Jan 15, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
01:39 AM
Frequently Asked Questions
1
What is CVE-2018-20713?
CVE-2018-20713 is a vulnerability in Shopware before version 5.4.3 that allows SQL Injection by remote authenticated users.
2
How severe is CVE-2018-20713?
CVE-2018-20713 has a severity rating of 8.8, which is considered high.
3
How can I fix CVE-2018-20713?
To fix CVE-2018-20713, update Shopware to version 5.4.3 or above.
4
Where can I find more information about CVE-2018-20713?
You can find more information about CVE-2018-20713 at the following references: [link1], [link2], [link3].
5
What is the Common Weakness Enumeration (CWE) for CVE-2018-20713?
The CWE for CVE-2018-20713 is CWE-89, which is a vulnerability related to improper neutralization of special elements used in an SQL command.