CVE-2022-36101

MEDIUM

Shopware < 5.7.15 - Exposure of Sensitive Information in Backend Customer Detail View

Title source: llm
STIX 2.1

Description

Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are advised to update and may get the update either via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

References (4)

Core 4

Scores

CVSS v3 5.4
EPSS 0.0053
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
shopware/shopware 0 - 5.7.15Packagist
shopware/shopware 5.0.0 - 5.7.15
Published Sep 12, 2022
Tracked Since Feb 18, 2026