Aller au contenu

Fiche vulnérabilité

CVE-2022-24879 : faille élevée shopware shopware (CVSS 7.5)

Description

Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
28 avr. 2022
Dernière mise à jour
23 avr. 2025

Produits concernés

  • shopware shopware

Références

Rechercher une autre vulnérabilité dans la base CVE