Skip to content

GHSA-2qxr-vvj4-5934 GHSA-r432-q883-wgvf GHSA-8xfc-pww7-3rm5 GHSA-p589-2ff8-3wfw GHSA-mch6-932v-3cm8

Shopware 6.7.14.1 and 6.6.10.25 fix SQL injection, webhook and privilege escalation flaws

Critical 9.6 Vendor: Shopware Published

Shopware has released 6.7.14.1 and 6.6.10.25 to fix five security advisories: Store API SQL injection, webhook permission bypass, two privilege escalation flaws and a newsletter double opt-in bypass. Operators should upgrade.

What happened

Shopware has published five security advisories for its e-commerce platform. GHSA-2qxr-vvj4-5934 allows an unauthenticated Store API client to read arbitrary data from the underlying database through SQL injection, but only where the shop runs on PHP before version 8.4 with PDO MySQL emulated prepares enabled. Write access has not been established. GHSA-r432-q883-wgvf is a webhook permission flaw with critical severity: a user or integration with webhook creation privileges could receive customer, order, business-process or email-related event data beyond its assigned permissions, and in some cases account-recovery information.

The remaining three advisories cover authenticated privilege escalation and consent integrity. GHSA-8xfc-pww7-3rm5 lets a user with user_change_me promote their own account to administrator. GHSA-p589-2ff8-3wfw lets a user with user:create bypass authorisation checks when cloning users and set protected fields. GHSA-mch6-932v-3cm8 allows an unauthenticated Store API caller to activate a newsletter subscription without proving control of the email address when double opt-in is enabled. Shopware has not said whether any of these is under active exploitation.

Who is affected

All five advisories affect Shopware 6.7.0.0 through 6.7.14.0, and all Shopware versions before 6.6.10.25, including 6.5.x and earlier and 6.6.0.0 through 6.6.10.24. The SQL injection additionally requires PHP before version 8.4 with PDO MySQL emulated prepares enabled. Shopware stores are typically public-facing web applications holding customer and order data; both the storefront and the administration interface should be included in exposure reviews.

What to do now

  1. Upgrade to the fixed release: Shopware 6.7.14.1 for installations on 6.7.0.0 through 6.7.14.0, or Shopware 6.6.10.25 for installations on versions before 6.6.10.25.
  2. If you cannot patch immediately, apply the vendor workarounds: for the SQL injection, upgrade to PHP 8.4 or later, or set PDO::ATTR_EMULATE_PREPARES to false; restrict webhook:create to trusted administrators and integrations, and review existing webhook registrations and delivery logs; remove user_change_me from roles that do not need profile self-editing, and remove user:create or other unnecessary create permissions from untrusted roles; review administrator accounts and audit logs for unexpected changes; restrict Administration API access to trusted users and networks; and disable public newsletter subscriptions until patched.
  3. After upgrading, rotate credentials or recovery tokens if unauthorised webhook activity or unexpected privilege changes are found.

How to detect it

Review webhook registrations and delivery logs for unexpected entries or event data outside the expected scope. Review administrator accounts and audit logs for unexpected privilege changes, especially from accounts holding only user_change_me or user:create. For the newsletter issue, compare newsletter subscriptions with double opt-in confirmation logs if public subscriptions were enabled.

Beyond the patch

Shopware shops are public-facing and process customer and order data, so the unauthenticated SQL injection and access-control gaps should be treated as a priority rather than a routine platform update. Our Virtual CISO Services help identify exposed storefront and administration interfaces before an advisory lands, and Implementation & Assessment Services can test and harden the shop platform against input-validation and access-control failures.

Affected and fixed versions

ProductAffectedFixed in
GHSA-2qxr-vvj4-5934
Shopware
6.7.0.0 – < 6.7.14.1
– < 6.6.10.25
6.7.0.0 – < 6.7.14.1
– < 6.6.10.25
6.7.14.1
6.6.10.25
5, 6.7.14.1
GHSA-r432-q883-wgvf
Shopware
6.7.0.0 – < 6.7.14.1
6.7.0.0 – < 6.7.14.1
– < 6.6.10.25
– < 6.6.10.25
6.7.14.1
6.6.10.25
5, 6.7.14.1
GHSA-8xfc-pww7-3rm5, GHSA-p589-2ff8-3wfw
Shopware
6.7.0.0 – < 6.7.14.1
– < 6.6.10.25
– < 6.6.10.25
6.7.0.0 – < 6.7.14.1
6.7.14.1
6.6.10.25
5, 6.7.14.1
GHSA-mch6-932v-3cm8
Shopware
– < 6.6.10.25
– < 6.6.10.25
6.7.0.0 – < 6.7.14.1
6.7.0.0 – < 6.7.14.1
6.6.10.25
6.7.14.1
5, 6.7.14.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.