Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 6.6.5.1和6.5.8.13及之前版本存在安全漏洞,该漏洞源于其store-API在处理Criteria时没有正确考虑ManyToMany关联,导致某些保护措施没有被适当使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-42355 | 8.3 HIGH | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence ta |
| CVE-2024-42356 | 8.3 HIGH | Shopware vulnerable to Server Side Template Injection in Twig using Context functions |
| CVE-2024-42357 | 7.3 HIGH | Shopware vulnerable to blind SQL-injection in DAL aggregations |
No comments yet