GHSA-3867-jc5c-66qf
GitHub Security Advisory
Broken Access Control order API in Shopware
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write' permissions for orders are still able to change the order state.
### Patches
Update to Shopware 6.5.7.4
### Workarounds
For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Affected Packages
Packagist
shopware/core
Affected versions:
0
(fixed in 6.5.7.4)
Packagist
shopware/platform
Affected versions:
0
(fixed in 6.5.7.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.