Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 存在授权问题漏洞,该漏洞源于不正确的 api 路由检查。攻击者可以在没有应用权限的情况下修改客户和创建订单。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24747 | 6.3 MEDIUM | HTTP caching is marking private HTTP headers as public |
| CVE-2022-24746 | 6.1 MEDIUM | HTML injection possibility in voucher code form |
| CVE-2022-24745 | 4.8 MEDIUM | Guest session is shared between customers in shopware |
| CVE-2022-24744 | 2.6 LOW | Insufficient Session Expiration in shopware |
No comments yet