CVE-2022-36102

MEDIUM

Shopware <5.7.15 - Auth Bypass

Title source: llm
STIX 2.1

Description

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current version (5.7.15). Users can get the update via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

Scores

CVSS v3 6.3
EPSS 0.0061
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281
Status published
Products (2)
shopware/shopware 0 - 5.7.15Packagist
shopware/shopware 5.0.0 - 5.7.15
Published Sep 12, 2022
Tracked Since Feb 18, 2026