CVE-2025-67648 | Shopware up to 6.7.5.1 Request Parameter AuthController.php cross site scripting (GHSA-6w82-v552-wjw2)
A vulnerability, which was classified as problematic, has been found in Shopware up to 6.7.5.1. This affects an unknown part of the file AuthController.php of the component Request Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-67648. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.