Home

Description

A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

PUBLISHED Reserved 2025-07-21 | Published 2025-08-06 | Updated 2025-11-03 | Assigner SEC-VLab




MEDIUM: 6.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N

Problem types

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Product status

Default status
unaffected

6.6.x
affected

6.7.x
affected

Credits

Timo Müller finder

References

github.com/shopware/shopware/issues/11245 exploit

seclists.org/fulldisclosure/2025/Aug/17

github.com/shopware/shopware/issues/11245 issue-tracking

cve.org (CVE-2025-7954)

nvd.nist.gov (CVE-2025-7954)

Download JSON