First published: Wed Mar 09 2022(Updated: )
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | <6.4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-24746.
The severity level of CVE-2022-24746 is medium (CVSS score: 6.1).
The affected software is Shopware version up to and excluding 6.4.8.1.
Code injection can be done via the voucher code form.
You can fix CVE-2022-24746 by updating to Shopware version 6.4.8.1, the patched version.