PT-2023-24671 · Shopware · Shopware

CVE-2023-34099

·

Publicado

2023-06-27

·

Atualizado

2023-07-06

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopware versions prior to 5.7.18
Description The mail validation in the registration process had flaws, allowing the construction of different mail addresses that result in the same address, which can be shared by multiple accounts.
Recommendations For versions prior to 5.7.18, update to version 5.7.18 to address the issue. For older versions, consider using the Security Plugin as a mitigation measure.

Exploit

Correção

DoS

Improper Check for Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34099
GHSA-GH66-FP7J-98V5

Produtos afetados

Shopware