CVE-2025-67648
Last modified
CVE-2025-67648 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter, waitTime, which lacks proper input validation. This issue is fixed in versions 6.6.10.10 and 6.7.5.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Shopware | Shopware | >= 6.4.6.0, < 6.6.10.10 |
| Shopware | Shopware | >= 6.7.0.0, < 6.7.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67648?
How severe is CVE-2025-67648?
How do I fix CVE-2025-67648?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67642Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earli…4.3
- CVE-2025-67643Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b…4.3
- CVE-2025-67644LangGraph SQLite Checkpoint is an implementation of LangGrap…7.8
- CVE-2025-67645OpenEMR is a free and open source electronic health records …8.8
- CVE-2025-67646TableProgressTracking is a MediaWiki extension to track prog…3.5
- CVE-2025-67647SvelteKit is a framework for rapidly developing robust, perf…9.1
- CVE-2025-67649A SQL injection vulnerability has been identified in PHP Jab…9.3
- CVE-2025-6765A vulnerability, which was classified as critical, has been …8.8
- CVE-2025-67650An authenticated SQL injection vulnerability has been identi…8.6
- CVE-2025-67651A Cross-Site Request Forgery (CSRF) vulnerability has been i…6.9
- CVE-2025-67652An attacker with access to the project file could use the ex…6.1
- CVE-2025-67653Advantech WebAccess/SCADA is vulnerable to directory travers…7.5
Are you affected by CVE-2025-67648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
