Tag
#auth
### Impact When a authentificated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally. ### Patches The problem has been fixed with Shopware 6.6.1.0 and 6.5.8.8. ### Workarounds When you are not able to update, you can install the latest version of the Shopware Security Plugin.
Invision Community versions 4.7.16 and below suffer from a remote code execution vulnerability in toolbar.php.
Invision Community versions 4.4.0 through 4.7.15 suffer from a remote SQL injection vulnerability in store.php.
Open eShop version 2.7.0 suffers from a cross site scripting vulnerability.
HTMLy version 2.9.6 suffers from a persistent cross site scripting vulnerability.
UP-RESULT version 0.1 2024 suffers from a remote SQL injection vulnerability.
Trojan.Win32.Razy.abc malware suffers from an insecure permissions vulnerability.
AnyDesk version 7.0.15 suffers from an unquoted service path vulnerability.
By Daily Contributors Today over at Resonance Security I am going to look at one of the more unusual ways in… This is a post from HackRead.com Read the original post: The Legacy of a Security Breach
An ongoing cyberattack campaign with apparent ties to China uses a new version of sophisticated JavaScript remote access Trojan JSOutProx and is now targeting banks in the Middle East.