Vulnerability DatabaseGHSA-8pfh-mm2g-hmc3

GHSA-8pfh-mm2g-hmc3
PHP vulnerability analysis and mitigation

Overview

An authenticated Server-Side Request Forgery (SSRF) vulnerability was identified in Shopware, affecting both shopware/core and shopware/platform Composer packages versions 6.3.4.0 and earlier. The vulnerability was disclosed on December 15, 2020, and was assigned the identifier GHSA-8pfh-mm2g-hmc3. This security issue was discovered by REQON B.V. and was given a low severity rating (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and received a low severity assessment. No CVE identifier was assigned to this vulnerability. The issue affects the Shopware e-commerce platform, specifically impacting versions up to and including 6.3.4.0 of both shopware/core and shopware/platform packages (GitHub Advisory).

Impact

The vulnerability allows authenticated users to perform Server-Side Request Forgery attacks against the affected Shopware installations. Given the low severity rating and the requirement for authentication, the potential impact appears to be limited (GitHub Advisory).

Exploitability

The vulnerability requires authentication to exploit, which significantly reduces its exploitability in the wild. No public exploits or active exploitation have been reported (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 6.3.4.1 of both affected packages. Users are recommended to update to this version through the Auto-Updater or via the download overview. For older versions (6.1 and 6.2), a plugin-based fix is available through the Shopware store. Detailed information about the security update can be found in Shopware's security documentation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management