First published: Thu Apr 28 2022(Updated: )
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopware Shopware | >=5.2.0<5.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-24879.
The severity of CVE-2022-24879 is high with a CVSS score of 7.5.
CVE-2022-24879 affects Shopware versions prior to 5.7.9.
The vulnerability allows for the malfunction of CSRF token validation, potentially leading to cross-site request forgery attacks.
The issue is fixed in version 5.7.9 of Shopware, so users should upgrade to this version to mitigate the vulnerability.