Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:NDefault status
unaffected
6.6.x
affected
6.7.x
affected
Description
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
Problem types
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Product status
6.6.x
6.7.x
Credits
Timo Müller
References
github.com/shopware/shopware/issues/11245
seclists.org/fulldisclosure/2025/Aug/17
github.com/shopware/shopware/issues/11245