CVE-2022-24892: Multiple valid tokens for password reset in Shopware
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24892?
The severity of CVE-2022-24892 is high with a severity value of 7.5.
How does CVE-2022-24892 affect Shopware?
CVE-2022-24892 affects Shopware versions 5.0.4 to 5.7.9.
What is the vulnerability in CVE-2022-24892?
CVE-2022-24892 allows an attacker to take over a victim's account by using multiple password reset tokens.
How can I fix CVE-2022-24892?
To fix CVE-2022-24892, update Shopware to version 5.7.9 or later.
Where can I find more information about CVE-2022-24892?
You can find more information about CVE-2022-24892 in the following references: [Shopware Security Updates](https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-04-2022), [Shopware GitHub Advisory](https://github.com/shopware/shopware/security/advisories/GHSA-3qrq-r688-vvh4), [Shopware Changelog](https://www.shopware.com/en/changelog-sw5/#5-7-9).