seggewiss

Learning IT security in public — eJPT, CPTS, OSCP, and what actually happens along the way.

Appsec

Two Critical Bugs in Shopware's App System

I found two critical bugs in Shopware 6. One is a sandbox escape in App Scripts, one is a stored SQL injection through custom entities. Both break the same trust boundary: the App. Reported, fixed, credited, and now public. No exploit details.