{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T19:24:51.968","vulnerabilities":[{"cve":{"id":"CVE-2023-22730","sourceIdentifier":"security-advisories@github.com","published":"2023-01-17T22:15:10.867","lastModified":"2024-11-21T07:45:18.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin. \n"},{"lang":"es","value":"Shopware es una plataforma de comercio de código abierto basada en Symfony Framework y Vue js. En las versiones afectadas, era posible colocar la misma línea de pedido varias veces en el carrito utilizando el AP. Los validadores de carrito verificaron la individualidad del artículo de línea y el usuario pudo evitar los límites de cantidad en las ventas. Este problema se ha solucionado con la versión 6.4.18.1. Los usuarios de las versiones principales 6.1, 6.2 y 6.3 también pueden obtener esta solución a través de un complemento."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*","versionEndExcluding":"6.4.18.1","matchCriteriaId":"1BE11635-1060-43A5-B8E6-6A9335AECCDE"}]}]}],"references":[{"url":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates","source":"security-advisories@github.com","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/shopware/platform/commit/4fce12096e54b2033832d9104fa2e68888c2b4e9","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/shopware/platform/security/advisories/GHSA-8r6h-m72v-38fg","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-01-2023?category=security-updates","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/shopware/platform/commit/4fce12096e54b2033832d9104fa2e68888c2b4e9","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/shopware/platform/security/advisories/GHSA-8r6h-m72v-38fg","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}