Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
History

Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
Description Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Title Shopware allows Denial Of Service via password length
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-08T13:46:30.629Z

Updated: 2025-04-08T18:47:54.011Z

Reserved: 2025-03-17T12:41:42.565Z

Link: CVE-2025-30151

cve-icon Vulnrichment

Updated: 2025-04-08T18:47:26.069Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T14:15:34.737

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-30151

cve-icon Redhat

No data.