Record summary

CVE-2025-30151 has a selected CVSS score of 7.5 (high).

Description

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 6.5.8.17affected
>= 6.6.0.0, < 6.6.10.3affected
>= 6.7.0.0-rc1, < 6.7.0.0-rc2affected
GitHub Advisory6.6.0.0 to < 6.6.10.3 · Fixed in 6.6.10.3affected
6.7.0.0-rc1 to < 6.7.0.0-rc2 · Fixed in 6.7.0.0-rc2affected
Before 6.5.8.17 · Fixed in 6.5.8.17affected
GitHub Advisory6.6.0.0 to < 6.6.10.3 · Fixed in 6.6.10.3affected
6.7.0.0-rc1 to < 6.7.0.0-rc2 · Fixed in 6.7.0.0-rc2affected
Before 6.5.8.17 · Fixed in 6.5.8.17affected

References

6