GHSA-r2vg-hvjm-fg38
Dashboard / Vulnerabilities / GHSA-r2vg-hvjm-fg38
GHSA-r2vg-hvjm-fg38
Summary: Shopware Customer Orders can be canceled, even if refunds are disabled
Details: Refunds in general can be enabled through the administration setting `core.cart.enableOrderRefunds` (in the cart panel).Which visually shows and hides the button. However, using a custom crafted request, a customer can still cancel his own orders.As this is not checked inside the route (and also not in the controller): https://github.com/shopware/shopware/blob/trunk/src/Storefront/Controller/AccountOrderController.php#L98 https://github.com/shopware/shopware/blob/trunk/src/Core/Checkout/Order/SalesChannel/CancelOrderRoute.php To mitigate this, a check should be added to the `CancelOrderRoute` which verifies that the feature is enabled.
References: https://github.com/shopware/shopware/security/advisories/GHSA-r2vg-hvjm-fg38, https://github.com/shopware/shopware/commit/b157508aef2c820e7ff89ebd5848d3019f22b592, https://github.com/shopware/shopware
Affected packages
Package
Name: shopware/platform
Purl: pkg:composer/shopware/platform
Affected ranges
Type: ECOSYSTEM
Events:
