The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade shopware/platform
to version 6.4.18.1 or higher.
shopware/platform is a Shopware e-commerce core.
Affected versions of this package are vulnerable to Information Exposure in the output of the log module, which can contain password reset email text. An attacker with access to either the local system logs or a centralized logging store can access these logs.
This vulnerability can be avoided by removing the log module ACL rights from all relevant users, or disabling logging.