CVE-2022-24746

MEDIUM

Shopware - Code Injection

Title source: llm
STIX 2.1

Description

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in version 6.4.8.1. There are no known workarounds for this issue.

Scores

CVSS v3 6.1
EPSS 0.0040
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
shopware/core 0 - 6.4.8.1Packagist
shopware/platform 0 - 6.4.8.1Packagist
shopware/shopware < 6.4.8.1
shopware/storefront 0 - 6.4.8.1Packagist
Published Mar 09, 2022
Tracked Since Feb 18, 2026