CVE-2025-67648: Shopware's inproper input validation can lead to Reflected XSS through Storefront Login Page

Published Dec 9, 2025
·
Updated

Impact

By exploiting the XSS vulnerabilities, malicious actors can perform harmful actions in the user's web browser in the session context of the affected user. Some examples of this include, but are not limited to: Obtaining user session tokens. Performing administrative actions (when an administrative user is affected). These vulnerabilities pose a high security risk. Since a sensitive cookie is not configured with the HttpOnly attribute and administrator JWTs are stored in sessionStorage, any successful XSS attack could enable the theft of session cookies and administrative tokens.

Description

A request parameter from the URL of the login page is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter. An attacker can create malicious links that could be used in a phishing attack. The parameter waitTime lacks proper input validation.

The attack can be tested with the following URL pattern:

/account/login?loginError=1&waitTime=<a%20href%3D"https%3A%2F%2Fde.wikipedia.org%2Fwiki%2FPhishing">Here<%2Fa>

The same applies to the errorSnippet parameter:

/account/login?loginError=1&errorSnippet=Reset%20your%20password%20%3Ca%20href%3D%22https%3A%2F%2Fde.wikipedia.org%2Fwiki%2FPhishing%22%3Ehere%3C%2Fa%3E.

Other sources

Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.

MITRE

Affected Software

6 affected componentsFixes available
composer/shopware/storefront>=6.7.0.0<6.7.5.1
6.7.5.1
composer/shopware/shopware>=6.7.0.0<6.7.5.1
6.7.5.1
composer/shopware/storefront>=6.4.6.0<6.6.10.10
6.6.10.10
composer/shopware/shopware>=6.4.6.0<6.6.10.10
6.6.10.10
Shopware Shopware>=6.4.6.0<6.6.10.10
Shopware Shopware>=6.7.0.0<6.7.5.1

Event History

Dec 9, 2025
Advisory Published
via GitHub·05:24 PM
Data Sourced
via GitHub·05:24 PM
DescriptionSeverityWeaknessAffected Software
Dec 10, 2025
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
DescriptionSeverityWeakness
Dec 11, 2025
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 AM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-67648?

CVE-2025-67648 is considered a high severity vulnerability due to its potential to allow XSS attacks that can compromise user sessions.

2

How do I fix CVE-2025-67648?

To fix CVE-2025-67648, you should update Shopware and storefront packages to version 6.7.5.1 or 6.6.10.10 as applicable.

3

What are the risks associated with CVE-2025-67648?

The risks associated with CVE-2025-67648 include unauthorized access to user session tokens and the ability for attackers to perform actions in a user's session.

4

Which versions of Shopware are affected by CVE-2025-67648?

CVE-2025-67648 affects Shopware versions from 6.4.6.0 to 6.7.5.1.

5

Can CVE-2025-67648 lead to data theft?

Yes, CVE-2025-67648 can potentially lead to data theft if an attacker successfully exploits the XSS vulnerability to hijack user sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203