Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade shopware/core to version 6.6.10.7, 6.7.3.1 or higher.
shopware/core is a Shopware platform is the core for all Shopware ecommerce products.
Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer via the import/export profile functionality in the admin export section. An attacker can access sensitive user information, including password hashes and reset tokens, by creating a custom mapping in the export profile and generating an export file.