Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-03218
HistoryJan 06, 2022 - 12:00 a.m.

Shopware Trust Management Issue Vulnerability

2022-01-0600:00:00
China National Vulnerability Database
www.cnvd.org.cn
3

0.001 Low

EPSS

Percentile

42.3%

Shopware is a suite of open source e-commerce software from the German company Shopware.A trust management issue vulnerability exists in versions of Shopware prior to 5.7.7, which stems from the fact that shopware does not invalidate a user’s session when a password is changed. An attacker could use this vulnerability to gain access to a valid user session.

CPENameOperatorVersion
Shopware Shopware >=5.7.3,lt5.7.7

0.001 Low

EPSS

Percentile

42.3%