CVE-2022-36101 MEDIUM

CVE-2022-36101: Sensitive data in backend customer module

Vendor Shopware
Product shopware
Weakness CWE-200 · Info exposure
Published September 12, 2022
Last update April 23, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are advised to update and may get the update either via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

September 12, 2022 CVE published
April 23, 2025 Record updated