shopware/core is vulnerable to Weak Password Recovery Mechanism
93
Critical Risk
Shopware's Administration password-recovery flow builds reset links from the incoming Host header without sufficient validation. An unauthenticated attacker who knows an administrator's email can trigger a reset so the emailed link points at a domain they control. If the administrator opens that link, the attacker captures the reset token and takes over the account with full Administration access. The fix validates the host used in password-reset links.
You are affected if you are using a version that falls within the vulnerable range and the Administration password-recovery flow is reachable without Host-header pinning, such as Symfony trusted_hosts or equivalent reverse-proxy filtering.
shopware/core is vulnerable to Weak Password Recovery Mechanism in versions 0.0.0.1 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant