shopware/core is vulnerable to Remote Code Execution (RCE)
96
Critical Risk
shopware/core App Scripts can bypass their intended sandbox restrictions. A malicious or compromised App that is installed and activated can execute arbitrary PHP functions and operating-system commands with the privileges of the PHP/web-server process. That can expose configuration and credentials, change writable files, reach internal services, or disrupt the shop.
You are affected if you are using a version that falls within the vulnerable range and have Apps installed and activated.
shopware/core is vulnerable to Remote Code Execution (RCE) in versions 6.5.4.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant