shopware/core is vulnerable to SQL Injection
91
Critical Risk
shopware/core interpolates custom-entity and field names from an App or plugin Resources/entities.xml into SQL and DDL as table and column names without validating the identifiers. A malicious or compromised extension can therefore run arbitrary SQL with Shopware's database connection, including reading, changing, or deleting shop data and altering the schema. The patch allow-lists those names when the App or plugin is installed or updated so they may only contain letters, digits, underscores, $, and MySQL/MariaDB-supported non-ASCII bytes.
You are affected if you are using a version that falls within the vulnerable range and you install or update Apps or plugins that define custom entities.
shopware/core is vulnerable to SQL Injection in versions 6.4.16.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant