CVE-2025-30150 | Shopware up to 6.5.8.17/6.6.10.3/6.7.0.0-rc1 API Endpoint recovery-password observable response discrepancy (GHSA-hh7j-6x3q-f52h)
A vulnerability, which was classified as problematic, has been found in Shopware up to 6.5.8.17/6.6.10.3/6.7.0.0-rc1. This issue affects some unknown processing of the file /store-api/account/recovery-password of the component API Endpoint. The manipulation leads to observable response discrepancy.
This vulnerability is uniquely identified as CVE-2025-30150. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.