Shopware
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*
- >= 7.0.0, < 7.8.1
- < 6.10.15
An information disclosure vulnerability has been identified in Shopware's commercial package, specifically in versions 7.0.0 prior to 7.8.1 and versions prior to 6.10.15. The vulnerability arises because the '/api/_info/config' route exposes sensitive information about activated licenses and features. This could lead to an unwanted exposure of the system's state.
Exploitation of this vulnerability could result in unauthorized access to license information and features, potentially revealing the system's state and configuration.
Users can upgrade to Shopware versions 7.8.1 or 6.10.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.