GHSA-2qxr-vvj4-5934 GHSA-r432-q883-wgvf GHSA-8xfc-pww7-3rm5 GHSA-p589-2ff8-3wfw GHSA-mch6-932v-3cm8
Shopware 6.7.14.1 and 6.6.10.25 fix SQL injection, webhook and privilege escalation flaws
Shopware has released 6.7.14.1 and 6.6.10.25 to fix five security advisories: Store API SQL injection, webhook permission bypass, two privilege escalation flaws and a newsletter double opt-in bypass. Operators should upgrade.
What happened
Shopware has published five security advisories for its e-commerce platform. GHSA-2qxr-vvj4-5934 allows an unauthenticated Store API client to read arbitrary data from the underlying database through SQL injection, but only where the shop runs on PHP before version 8.4 with PDO MySQL emulated prepares enabled. Write access has not been established. GHSA-r432-q883-wgvf is a webhook permission flaw with critical severity: a user or integration with webhook creation privileges could receive customer, order, business-process or email-related event data beyond its assigned permissions, and in some cases account-recovery information.
The remaining three advisories cover authenticated privilege escalation and consent integrity. GHSA-8xfc-pww7-3rm5 lets a user with user_change_me promote their own account to administrator. GHSA-p589-2ff8-3wfw lets a user with user:create bypass authorisation checks when cloning users and set protected fields. GHSA-mch6-932v-3cm8 allows an unauthenticated Store API caller to activate a newsletter subscription without proving control of the email address when double opt-in is enabled. Shopware has not said whether any of these is under active exploitation.
Who is affected
All five advisories affect Shopware 6.7.0.0 through 6.7.14.0, and all Shopware versions before 6.6.10.25, including 6.5.x and earlier and 6.6.0.0 through 6.6.10.24. The SQL injection additionally requires PHP before version 8.4 with PDO MySQL emulated prepares enabled. Shopware stores are typically public-facing web applications holding customer and order data; both the storefront and the administration interface should be included in exposure reviews.
What to do now
- Upgrade to the fixed release: Shopware 6.7.14.1 for installations on 6.7.0.0 through 6.7.14.0, or Shopware 6.6.10.25 for installations on versions before 6.6.10.25.
- If you cannot patch immediately, apply the vendor workarounds: for the SQL injection, upgrade to PHP 8.4 or later, or set PDO::ATTR_EMULATE_PREPARES to false; restrict
webhook:createto trusted administrators and integrations, and review existing webhook registrations and delivery logs; removeuser_change_mefrom roles that do not need profile self-editing, and removeuser:createor other unnecessary create permissions from untrusted roles; review administrator accounts and audit logs for unexpected changes; restrict Administration API access to trusted users and networks; and disable public newsletter subscriptions until patched. - After upgrading, rotate credentials or recovery tokens if unauthorised webhook activity or unexpected privilege changes are found.
How to detect it
Review webhook registrations and delivery logs for unexpected entries or event data outside the expected scope. Review administrator accounts and audit logs for unexpected privilege changes, especially from accounts holding only user_change_me or user:create. For the newsletter issue, compare newsletter subscriptions with double opt-in confirmation logs if public subscriptions were enabled.
Beyond the patch
Shopware shops are public-facing and process customer and order data, so the unauthenticated SQL injection and access-control gaps should be treated as a priority rather than a routine platform update. Our Virtual CISO Services help identify exposed storefront and administration interfaces before an advisory lands, and Implementation & Assessment Services can test and harden the shop platform against input-validation and access-control failures.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-2qxr-vvj4-5934 Shopware | 6.7.0.0 – < 6.7.14.1 – < 6.6.10.25 6.7.0.0 – < 6.7.14.1 – < 6.6.10.25 | 6.7.14.1 6.6.10.25 5, 6.7.14.1 |
| GHSA-r432-q883-wgvf Shopware | 6.7.0.0 – < 6.7.14.1 6.7.0.0 – < 6.7.14.1 – < 6.6.10.25 – < 6.6.10.25 | 6.7.14.1 6.6.10.25 5, 6.7.14.1 |
| GHSA-8xfc-pww7-3rm5, GHSA-p589-2ff8-3wfw Shopware | 6.7.0.0 – < 6.7.14.1 – < 6.6.10.25 – < 6.6.10.25 6.7.0.0 – < 6.7.14.1 | 6.7.14.1 6.6.10.25 5, 6.7.14.1 |
| GHSA-mch6-932v-3cm8 Shopware | – < 6.6.10.25 – < 6.6.10.25 6.7.0.0 – < 6.7.14.1 6.7.0.0 – < 6.7.14.1 | 6.6.10.25 6.7.14.1 5, 6.7.14.1 |
References
Vendor advisory
- SQL injection in Store API aggregation handling on PHP < 8.4
- Webhook permission can bypass event ACLs and expose sensitive data
- Privilege escalation through insufficient authorization in profile updates
- Improper authorization in entity cloning enables privilege escalation
- Shopware newsletter double-opt-in bypass