CVE-2020-13997

HIGH

Shopware < 6.2.3 - Unauthenticated Sensitive Information Exposure via Database Error Message

Title source: llm
STIX 2.1

Description

In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://www.shopware.com/en/changelog/#6-2-3

Scores

CVSS v3 7.5
EPSS 0.0149
EPSS Percentile 70.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-209
Status published
Products (3)
shopware/core 6.0.0 - 6.2.3Packagist
shopware/platform 6.0.0 - 6.2.3Packagist
shopware/shopware < 6.2.3
Published Jul 28, 2020
Tracked Since Feb 18, 2026