Shopware's log module vulnerable to Improper Output Neutralization
Description
Published by the National Vulnerability Database
Jan 17, 2023
Published to the GitHub Advisory Database
Jan 20, 2023
Reviewed
Jan 20, 2023
Last updated
Jan 25, 2023
Impact
The log module contains all kind of sent mails. It is possible to see the password reset email of customers and admin users to gain probably more access.
Patches
Update to the latest 6.4.18.1 version.
Workarounds
References
https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates
References