Weak Password Recovery Mechanism for Forgotten Password Affecting shopware/core package, versions <6.6.10.9>=6.7.0.0, <6.7.4.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Weak Password Recovery Mechanism for Forgotten Password vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SHOPWARECORE-14038293
  • published16 Nov 2025
  • disclosed14 Nov 2025
  • creditFlorianKe

Introduced: 14 Nov 2025

New CVE NOT AVAILABLE CWE-640  (opens in a new tab)

How to fix?

Upgrade shopware/core to version 6.6.10.9, 6.7.4.1 or higher.

Overview

shopware/core is a Shopware platform is the core for all Shopware ecommerce products.

Affected versions of this package are vulnerable to Weak Password Recovery Mechanism for Forgotten Password via the password reset, if a customer changes their email address after requesting a reset, the link associated with the previous email address remains valid. An attacker can gain unauthorized access to a user's account by using a previously issued password reset link after the user has changed their email address.

CVSS Base Scores

version 4.0
version 3.1