CVE-2021-32710 Information

Description

Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1 and 6.2 corresponding security measures are also available via a plugin. For the full range of functions we recommend updating to the latest Shopware version.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://github.com/shopware/platform/security/advisories/GHSA-h9q8-5gv2-v6mg https://github.com/shopware/platform/commit/010c0154bea57c1fca73277c7431d029db7a972e

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: