Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 6.6.5.1和6.5.8.13及之前版本存在安全漏洞,该漏洞源于其应用API中的搜索功能,aggregations对象中的name字段容易受到SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-42355 | 8.3 HIGH | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence ta |
| CVE-2024-42356 | 8.3 HIGH | Shopware vulnerable to Server Side Template Injection in Twig using Context functions |
| CVE-2024-42354 | 5.3 MEDIUM | Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api |
No comments yet