Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
https://www.redteam-pentesting.de/en/advisories/rt-sa-2025-001/
https://github.com/shopware/shopware/security/advisories/GHSA-8g35-7rmw-7f59
Published: 2025-04-15
Updated: 2025-04-23
Named Vulnerability: Shopware Security Plugin Vulnerability
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 6.8
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Severity: Medium
EPSS: 0.00014