Low severity3.7NVD Advisory· Published Jan 17, 2023· Updated Jun 17, 2026
CVE-2023-22732
CVE-2023-22732
Description
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when an attacker has stolen the session cookie they could use it for a long period of time. In version 6.4.18.1 an automatic logout into the Administration session has been added. As a result the user will be logged out when they are inactive. Users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.4.18.1 | 6.4.18.1 |
shopware/corePackagist | < 6.4.18.1 | 6.4.18.1 |
Affected products
4- shopware/platformv5Range: < 6.4.18.1
- ghsa-coords2 versions
< 6.4.18.1+ 1 more
- (no CPE)range: < 6.4.18.1
- (no CPE)range: < 6.4.18.1
Patches
Vulnerability mechanics
References
5- docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023nvdPatchVendor AdvisoryWEB
- github.com/shopware/platform/commit/cd7a89cbcd3a0428c6d1ef27b3aa15467a722ff6nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-59qg-93jg-236fghsaADVISORY
- github.com/shopware/platform/security/advisories/GHSA-59qg-93jg-236fnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-22732ghsaADVISORY
News mentions
0No linked articles in our index yet.