漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Shopware: Admin Account Takeover via User Recovery Hash Exposure
Vulnerability Description
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST /api/search/user-recovery, and using PATCH /api/_action/user/user-recovery/password; the root cause is that src/Core/System/User/Recovery/UserRecoveryDefinition.php exposes the hash field through the Admin API without ApiAware(false) or ReadProtection. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Shopware 信息泄露漏洞
Vulnerability Description
Shopware是德国Shopware公司开源的一套电子商务软件。 Shopware存在信息泄露漏洞,该漏洞源于UserRecoveryDefinition.php暴露哈希字段,可能导致具有user_recovery:read ACL的低权限管理员接管任意管理员账户。以下版本受到影响:6.6.10.18之前版本和6.7.10.1之前版本。
CVSS Information
N/A
Vulnerability Type
N/A