Executive brief
Shopware user session is not logged out if the password is reset via password recovery
Affected products
- Packagist shopware/core
- Packagist shopware/platform
Junglewise Threat Intelligence
CVE-2022-24744 · Severity: low · CVSS 3.1 · Published 2022-03-10
Technologies: shopware/core (Packagist), shopware/platform (Packagist). Vendors: Packagist.
Shopware user session is not logged out if the password is reset via password recovery