Lucene search

K
cve[email protected]CVE-2023-22730
HistoryJan 17, 2023 - 10:15 p.m.

CVE-2023-22730

2023-01-1722:15:10
CWE-20
web.nvd.nist.gov
30
shopware
commerce platform
bypassing
quantity limits
cart
fix
vulnerability
cve-2023-22730

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

28.7%

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item’s individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin.

Affected configurations

Vulners
NVD
Node
shopwareshopwareRange<6.4.18.1
VendorProductVersionCPE
shopwareshopware*cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "shopware",
    "product": "platform",
    "versions": [
      {
        "version": "< 6.4.18.1",
        "status": "affected"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

28.7%

Related for CVE-2023-22730