Loading HuntDB...

GHSA-3867-jc5c-66qf

GitHub Security Advisory

Broken Access Control order API in Shopware

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write' permissions for orders are still able to change the order state.

### Patches
Update to Shopware 6.5.7.4

### Workarounds
For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Affected Packages

Packagist shopware/core
Affected versions: 0 (fixed in 6.5.7.4)
Packagist shopware/platform
Affected versions: 0 (fixed in 6.5.7.4)

Related CVEs

Key Information

GHSA ID
GHSA-3867-jc5c-66qf
Published
January 17, 2024 8:29 PM
Last Modified
January 17, 2024 8:29 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
shopware/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.