Subscribe via feed.

Shopware 5.3.7 Cross Site Request Forgery

Posted by deepcore on March 14, 2018 – 12:30 am

Shopware versions 4.0.1 through 5.3.7 suffer from a cross site request forgery vulnerability. Malicious, third-party websites may abuse this API to list, add or remove products from a user’s cart.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.