{"id":"CVE-2024-42357","summary":"Shopware vulnerable to blind SQL-injection in DAL aggregations","details":"Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in the `aggregations` object. The `name` field in this `aggregations` object is vulnerable SQL-injection and can be exploited using SQL parameters. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.1, 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.","aliases":["GHSA-p6w9-r443-r752"],"modified":"2026-08-12T03:51:17.379618638Z","published":"2024-08-08T14:55:50.674Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42357.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42357.json"},{"type":"ADVISORY","url":"https://github.com/shopware/shopware/security/advisories/GHSA-p6w9-r443-r752"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42357"},{"type":"FIX","url":"https://github.com/shopware/core/commit/63c05615694790f5790a04ef889f42b764fa53c9"},{"type":"FIX","url":"https://github.com/shopware/core/commit/a784aa1cec0624e36e0ee4d41aeebaed40e0442f"},{"type":"FIX","url":"https://github.com/shopware/shopware/commit/57ea2f3c59483cf7c0f853e7a0d68c23ded1fe5b"},{"type":"FIX","url":"https://github.com/shopware/shopware/commit/8504ba7e56e53add6a1d5b9d45015e3d899cd0ac"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/shopware/core","events":[{"introduced":"c5635f75df71ab919c9dba907832dacea4fdc92f"},{"introduced":"0"},{"fixed":"63c05615694790f5790a04ef889f42b764fa53c9"},{"fixed":"a784aa1cec0624e36e0ee4d41aeebaed40e0442f"}],"database_specific":{"extracted_events":[{"introduced":"6.6.0.0"},{"last_affected":"6.6.5.0"},{"introduced":"0"},{"last_affected":"6.5.8.12"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/shopware/shopware","events":[{"introduced":"0"},{"fixed":"dcc24e9ec256787dc358feb1ac100d94d530db2f"},{"introduced":"b0ae9ef3fae80afcc4f38401c09037fa7adc57b0"},{"fixed":"e591422fb2720dcd24d9646f61437a8d2c857a96"},{"fixed":"57ea2f3c59483cf7c0f853e7a0d68c23ded1fe5b"},{"fixed":"8504ba7e56e53add6a1d5b9d45015e3d899cd0ac"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.5.8.13"},{"introduced":"6.6.0.0"},{"fixed":"6.6.5.1"}]}}],"versions":["v6.6.5.0","v6.5.8.12","v6.6.3.0","v6.5.8.11","v6.5.8.10","v6.5.8.9","v6.6.2.0","v6.5.8.8","v6.5.8.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42357.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}