shopware/core is vulnerable to SQL Injection
86
High Risk
Shopware's Store API aggregation handling prepends aggregation names to generated SQL as comment titles and previously rejected only ? and :. Names containing newline characters can terminate that comment and inject additional SQL. An unauthenticated attacker with a Sales Channel access key — commonly exposed by design in headless Store API integrations — can therefore manipulate the query and read sensitive data. The patch rejects aggregation names that contain line breaks and strips those characters from query titles before they are embedded in SQL.
You are affected if you are using a version that falls within the vulnerable range and the Store API is reachable. Sales Channel access keys are commonly public in headless integrations and should not be treated as sufficient protection against this issue.
shopware/core is vulnerable to SQL Injection in versions 6.6.0.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant