In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade shopware/core to version 6.6.10.7, 6.7.3.1 or higher.
shopware/core is a Shopware platform is the core for all Shopware ecommerce products.
Affected versions of this package are vulnerable to Incorrect Authorization in MediaVisibilityRestrictionSubscriber. A low‑privilege user can access sensitive customer data, such as addresses and payment-related information, by constructing aggregation queries that bypass authorization filters and enumerate private media records. Authorization filters are only injected during standard entity reads.