Description
Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/shopware/platform/security/advisories/GHSA-h9q8-5gv2-v6mg
Patch, Third Party Advisory x_refsource_misc
https://github.com/shopware/platform/commit/010c0154bea57c1fca73277c7431d029db7a972e
Scores
CVSS v3
5.9
EPSS
0.0088
EPSS Percentile
54.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-384
Status
published
Products (2)
shopware/platform
0 - 6.3.5.2Packagist
shopware/shopware
< 6.3.5.2
Published
Jun 24, 2021
Tracked Since
Feb 18, 2026