shopware/platform Security Advisories for v6.6.2.0 (4)
-
[HIGH] Shopware vulnerable to blind SQL-injection in DAL aggregations
PKSA-4jyx-mm79-zmg7 CVE-2024-42357 GHSA-p6w9-r443-r752
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[HIGH] Shopware vulnerable to Server Side Template Injection in Twig using Context functions
PKSA-69f8-ft32-qt99 CVE-2024-42356 GHSA-35jp-8cgg-p4wj
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[HIGH] Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
PKSA-44zj-btqf-vtmh CVE-2024-42355 GHSA-27wp-jvhw-v4xp
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub -
[MEDIUM] Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api
PKSA-c7v1-2zh3-y11f CVE-2024-42354 GHSA-hhcq-ph6w-494g
Affected version: >=6.6.0.0,<=6.6.5.0|<=6.5.8.12
Reported by:
GitHub