Shopware 6's password recovery link does not expire after email change
Moderate severity
GitHub Reviewed
Published
Nov 12, 2025
in
shopware/shopware
•
Updated Nov 14, 2025
Package
Affected versions
< 6.6.10.9
>= 6.7.0.0, < 6.7.4.1
Patched versions
6.6.10.9
6.7.4.1
Description
Published to the GitHub Advisory Database
Nov 14, 2025
Reviewed
Nov 14, 2025
Last updated
Nov 14, 2025
Summary
When a customer changes their email address after requesting a password reset, the old password reset link (tied to the previous email) remains valid. An attacker with access to the old email inbox is potentially able to reset the customer’s password even after the user changes their email address.
PoC
Impact
Reproduced on Stable 6.6.10.7 and trunk.
References