QID 996750

Date Published: 2024-01-23

QID 996750: PHP (Composer) Security Update for shopware/core (GHSA-3867-jc5c-66qf)

In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write' permissions for orders are still able to change the order state.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-3867-jc5c-66qf for updates and patch information.
    Vendor References

    CVEs related to QID 996750

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3867-jc5c-66qf shopware/core URL Logo github.com/advisories/GHSA-3867-jc5c-66qf