Shopware
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*
- <= 6.1.0
A vulnerability exists in Shopware versions through 6.1.0, where user sessions remain active after a password is reset via the password recovery process. This issue has been addressed in version 6.4.8.1. For users on older versions 6.1, 6.2, and 6.3, a plugin is available to implement the necessary security measures.
This vulnerability allows for user sessions to remain active even after a password reset, which could lead to unauthorized access if the session is hijacked.
Users are advised to update to Shopware version 6.4.8.2, available through the Auto-Updater or the Shopware download overview. For versions 6.1, 6.2, and 6.3, a plugin is available to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.