CVE-2026-48011: fallo de gravedad baja en shopware
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Publicada el · Actualizada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.7epss 0.4%
probabilidad de explotación
0.4%top 73% de las CVE
explotación observada
noninguna fuente lo reporta
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
shopware · shopwareCVEs relacionadas — shopware
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-32712MEDIUMInformation leakage in Error HandlerEPSS 1.1%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-21652LOWInsufficient Session Expiration in shopwareEPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%