Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10290 | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is no account for this customer. In contrast you get a success response if the account was found. This vulnerability is fixed in Shopware 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. |
Github GHSA |
GHSA-hh7j-6x3q-f52h | Shopware 6 allows attackers to check for registered accounts through the store-api |
Wed, 10 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:* cpe:2.3:a:shopware:shopware:6.7.0.0:rc1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Tue, 08 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is no account for this customer. In contrast you get a success response if the account was found. This vulnerability is fixed in Shopware 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. | |
| Title | Shopware 6 allows attackers to check for registered accounts through the store-api | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-08T18:46:21.570Z
Reserved: 2025-03-17T12:41:42.565Z
Link: CVE-2025-30150
Updated: 2025-04-08T18:46:14.744Z
Status : Analyzed
Published: 2025-04-08T14:15:34.540
Modified: 2025-09-10T15:24:57.090
Link: CVE-2025-30150
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:06Z
EUVD
Github GHSA