Total vulnerabilities in the database
Information exposure via query strings in URL
We recommend to update to the current version 6.3.4.1. You can get the update to 6.3.4.1 regularly via the Auto-Updater or directly via the download overview.
https://www.shopware.com/en/download/#shopware-6
For older versions of 6.1 and 6.2 the corresponding changes are also available via plugin:
https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-12-2020
We would like to thank <a rel="noopener" href="https://www.vater-it.de/">Oliver Herrmann</a> for reporting this issue.
Software | From | Fixed in |
---|---|---|
![]() |
- | 6.3.4.1 |
![]() |
- | 6.3.4.1 |