CVE-2023-34099

MEDIUM

Shopware 5.1.4-5.7.17 - Account Hijacking via Email Address Normalization Bypass

Title source: llm
STIX 2.1

Description

Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been addressed in version 5.7.18 and users are advised to update. There are no known workarounds for this vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (2)
shopware/shopware 5.1.4 - 5.7.17
shopware/shopware 5.1.4 - 5.7.18Packagist
Published Jun 27, 2023
Tracked Since Feb 18, 2026