CVE-2025-30150 Details
Description
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is no account for this customer. In contrast you get a success response if the account was found. This vulnerability is fixed in Shopware 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
A vulnerability in Shopware 6 allows attackers to verify if an email address is associated with an account by using the store-api endpoint '/store-api/account/recovery-password'. This issue affects Shopware versions 6.6.0.0 through 6.6.10.2, 6.7.0.0-rc1, and 6.5.8.17. The vulnerability is rooted in the way the store API handles account recovery requests, providing distinct responses based on account existence.
Users can update to Shopware version 6.6.10.3, 6.7.0.0-rc2, or 6.5.8.18. For those using older versions of 6.4, corresponding security measures are available via a plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shopware/shopware/security/advisories/GHSA-hh7j-6x3q-f52h | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shopware shopware | < 6.5.8.18 >= 6.6.0.0, < 6.6.10.3 6.7.0.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2025 | Initial Analysis | [email protected] |
| Apr 8, 2025 | New CVE Received | [email protected] |