VDB
Sign up
MEDIUM4.3

GHSA-r2vg-hvjm-fg38

Shopware Customer Orders can be canceled, even if refunds are disabled

Quick fix

GHSA-r2vg-hvjm-fg38 — shopware/platform: upgrade to the fixed version with the command below.

composer require shopware/platform:^6.7.3.1

Details

Refunds in general can be enabled through the administration setting `core.cart.enableOrderRefunds` (in the cart panel).Which visually shows and hides the button. However, using a custom crafted request, a customer can still cancel his own orders.As this is not checked inside the route (and also not in the controller): https://github.com/shopware/shopware/blob/trunk/src/Storefront/Controller/AccountOrderController.php#L98 https://github.com/shopware/shopware/blob/trunk/src/Core/Checkout/Order/SalesChannel/CancelOrderRoute.php

To mitigate this, a check should be added to the `CancelOrderRoute` which verifies that the feature is enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/platform
Introduced in: 6.7.0.0Fixed in: 6.7.3.1
Fixcomposer require shopware/platform:^6.7.3.1
Packagist/shopware/platform
Introduced in: 0Fixed in: 6.6.10.7
Fixcomposer require shopware/platform:^6.6.10.7
Packagist/shopware/core
Introduced in: 6.7.0.0Fixed in: 6.7.3.1
Fixcomposer require shopware/core:^6.7.3.1
Packagist/shopware/core
Introduced in: 0Fixed in: 6.6.10.7
Fixcomposer require shopware/core:^6.6.10.7

References