PT-2023-24671 · Shopware · Shopware
CVE-2023-34099
·
Publicado
2023-06-27
·
Atualizado
2023-07-06
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shopware versions prior to 5.7.18
Description
The mail validation in the registration process had flaws, allowing the construction of different mail addresses that result in the same address, which can be shared by multiple accounts.
Recommendations
For versions prior to 5.7.18, update to version 5.7.18 to address the issue. For older versions, consider using the Security Plugin as a mitigation measure.
Exploit
Correção
DoS
Improper Check for Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Shopware