ZeroHour
Sansec (Magento / e-commerce security)published ()ingested

Shopware fixes Store API vulnerability allowing administrator takeover

highVulnerabilityimportance 62
AI summary · glm-5.3-flash

Sansec discovered a Shopware 6 Store API flaw enabling administrator takeover; merchants should immediately update to 6.7.13.1 or 6.6.10.23.

Security firm Sansec discovered and confirmed a vulnerability in Shopware 6.7.12.2, then the latest stable release, that allows attackers to take over administrator accounts through the Store API. Shopware has released patches, and merchants are urged to update immediately to 6.7.13.1 or 6.6.10.23. No exploitation activity or CVE identifier is mentioned in the disclosure text.

  • Store API vulnerability permits administrator account takeover
  • Flaw found and confirmed by Sansec in Shopware 6.7.12.2
  • Fixed versions: 6.7.13.1 and 6.6.10.23
  • Merchants urged to patch immediately
Full article

Shopware merchants should update to 6.7.13.1 or 6.6.10.23 immediately. Sansec discovered and confirmed the vulnerability in Shopware 6.7.12.2, the latest stable release at the time of testing.An a...

This source does not provide full text. Read it at sansec.io.