Shopware fixes Store API vulnerability allowing administrator takeover
Sansec discovered a Shopware 6 Store API flaw enabling administrator takeover; merchants should immediately update to 6.7.13.1 or 6.6.10.23.
Security firm Sansec discovered and confirmed a vulnerability in Shopware 6.7.12.2, then the latest stable release, that allows attackers to take over administrator accounts through the Store API. Shopware has released patches, and merchants are urged to update immediately to 6.7.13.1 or 6.6.10.23. No exploitation activity or CVE identifier is mentioned in the disclosure text.
62