Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37013
HistorySep 13, 2022 - 6:38 a.m.

Information Disclosure

2022-09-1306:38:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
shopware security customer-info unauthorized-access

0.001 Low

EPSS

Percentile

44.6%

shopware/shopware is vulnerable to information disclosure. The vulnerability exists in getCustomer function in Customer.php because the hashed passwords and session IDs are exposed in the customer detail view which allows an attacker to gain access to sensitive information and perform unauthorized actions.

0.001 Low

EPSS

Percentile

44.6%

Related for VERACODE:37013