Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 6.6.5.1和6.5.8.13及之前版本存在安全漏洞,该漏洞源于漏洞源于其新的Twig标签,该标签用于静默化弃用消息,但由于参数没有正确转义,从而允许执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-42356 | 8.3 HIGH | Shopware vulnerable to Server Side Template Injection in Twig using Context functions |
| CVE-2024-42357 | 7.3 HIGH | Shopware vulnerable to blind SQL-injection in DAL aggregations |
| CVE-2024-42354 | 5.3 MEDIUM | Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api |
No comments yet