Vulnerability DatabaseGHSA-r2vg-hvjm-fg38

GHSA-r2vg-hvjm-fg38
PHP vulnerability analysis and mitigation

Overview

A vulnerability (GHSA-r2vg-hvjm-fg38) was discovered in Shopware's order cancellation functionality affecting versions >= 6.7.0.0, < 6.7.3.1 and < 6.6.10.7 of shopware/platform and shopware/core packages. The vulnerability allows customers to cancel their orders through custom-crafted requests even when the refund functionality is disabled in the system settings. This security issue was disclosed on October 21, 2025, and has been assigned a moderate severity rating with a CVSS score of 4.3 (GitHub Advisory).

Technical details

The vulnerability stems from a missing authorization check in the CancelOrderRoute class. While the administration setting 'core.cart.enableOrderRefunds' controls the visibility of the cancellation button in the user interface, the backend route does not verify this setting before processing cancellation requests. The issue affects the endpoint '/store-api/order/state/cancel' which processes order cancellation requests. The vulnerability has been assigned a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N, indicating network accessibility with low attack complexity and required privileges (GitHub Advisory).

Impact

The vulnerability allows authenticated customers to bypass the system's refund settings and cancel their orders even when this functionality is explicitly disabled by the store administrator. This could lead to unauthorized order cancellations and potential business process disruptions (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 6.7.3.1 and 6.6.10.7 of both shopware/platform and shopware/core packages. The fix implements a proper authorization check in the CancelOrderRoute class to verify that the refund feature is enabled before processing cancellation requests. Users are advised to upgrade to the patched versions (GitHub Advisory, Shopware Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-898v-775g-777cCRITICAL9.4
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-5j8p-438x-rgg5CRITICAL9.3
  • PHPPHP
  • onelogin/php-saml
NoYesDec 09, 2025
GHSA-j8g6-5gqc-mq36HIGH8.2
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-pvcv-q3q7-266gHIGH8.1
  • PHPPHP
  • filament/filament
NoYesDec 09, 2025
GHSA-6w82-v552-wjw2HIGH7.1
  • PHPPHP
  • shopware/shopware
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management