Vulnerabilities > CVE-2022-24744 - Insufficient Session Expiration vulnerability in Shopware

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
shopware
CWE-613

Summary

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions user sessions are not logged out if the password is reset via password recovery. This issue has been resolved in version 6.4.8.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

Vulnerable Configurations

Part Description Count
Application
Shopware
195

Common Weakness Enumeration (CWE)