Description
Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/shopware/platform/security/advisories/GHSA-g7w8-pp9w-7p32
Scores
CVSS v3
4.9
EPSS
0.0063
EPSS Percentile
45.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-306
Status
published
Products (2)
shopware/platform
0 - 6.4.1.1Packagist
shopware/shopware
< 6.4.1.1
Published
Jun 24, 2021
Tracked Since
Feb 18, 2026