Release notes Shopware 6.6.10.25
Abstract
Shopware 6.6.10.25 is a security release. Please update as soon as possible! If you cannot update for some reason it is strongly recommended to make use of the Security plugin.
System requirements
- tested on PHP 8.2 and 8.4
- tested on MySQL 8 and MariaDB 11
Improvements
(No notable improvements in this patch release)
Fixed bugs
Top 5 Most Important Bug Fixes
- GHSA-r432-q883-wgvf - Webhook ACL / sensitive webhook data exposure
- GHSA-2qxr-vvj4-5934 - Range-aggregation SQL injection
- GHSA-p589-2ff8-3wfw - User admin privilege escalation
- GHSA-8xfc-pww7-3rm5 - Integration admin privilege escalation via Sync API
- GHSA-mch6-932v-3cm8 - Newsletter double-opt-in bypass
Credits
Thanks to all diligent friends for helping us make Shopware better and better with each pull request!
More resources
- Detailed diff on Github to the former version
- Installation overview
- Update from a previous installation
Get in touch
Discuss about decisions, bugs you might stumble upon, etc in our community discord. See you there 😉