Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shopware unauthenticated data extraction possible through store-api.order endpoint
Vulnerability Description
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Shopware 安全漏洞
Vulnerability Description
Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 6.7.8.1之前版本和6.6.10.15之前版本存在安全漏洞,该漏洞源于对未验证客户的过滤器类型检查不足,可能导致访问其他客户的订单。
CVSS Information
N/A
Vulnerability Type
N/A