{"id":"GHSA-83jv-4prm-34g7","aliases":[],"url":"https://o3.security/vulnerability/GHSA-83jv-4prm-34g7","summary":"Shopware Remote Code Execution Vulnerability","details":"Under certain circumstances it is possible to execute an authorized foreign code in Shopware version prior to 5.2.25.\n","published":"2024-05-21T21:00:39Z","modified":"2024-12-06T05:35:31.476394Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/shopware","fixedVersion":"5.2.25"}],"fix":{"url":"https://github.com/shopware5/shopware/commit/8f6a7cefcba7547276892b82f64e4874c1a0dfed","label":"shopware5/shopware@8f6a7ce"},"references":[{"type":"WEB","url":"https://github.com/shopware5/shopware/commit/8f6a7cefcba7547276892b82f64e4874c1a0dfed"},{"type":"WEB","url":"https://community.shopware.com/_detail_2015.html"},{"type":"WEB","url":"https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2017?category=shopware-5-en/security-updates"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/shopware/shopware/2017-06-22.yaml"},{"type":"PACKAGE","url":"https://github.com/shopware5/shopware"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:35:31.476394Z"}}