Shopware
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*
- >= 6.7.0.0, < 6.7.6.1
A vulnerability exists in Shopware versions 6.7.0.0 prior to 6.7.6.1, where a regression of a previous security fix allows crafted PHP Closures to bypass allowed function checks in the Twig security extension. This issue could lead to improper control over code execution in Twig-rendered views.
Exploitation of this vulnerability could allow unauthorized PHP Closure objects to be passed into the Twig 'map' function, potentially leading to arbitrary code execution.
Users can upgrade to Shopware version 6.7.6.1 to address this vulnerability. Alternatively, the Shopware security plugin can be installed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.