Skip to content

Security: FriendsOfShopware/FroshPlatformAdminer

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x
< 2.0

Important Notice

This plugin provides direct database access through the Shopware Administration and is intended for development environments only. Do not use it in production.

Ensure that only trusted administrators with the system.frosh_adminer ACL permission have access.

Reporting a Vulnerability

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, use GitHub's private vulnerability reporting.

What to include

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Affected version(s)
  • Any potential fix or mitigation you have identified

What to expect

  • We review reported security issues as quickly as possible.
  • A security advisory will be published on GitHub after the fix is released.
  • You will be credited in the advisory (unless you prefer anonymity).
Learn more about advisories related to FriendsOfShopware/FroshPlatformAdminer in the GitHub Advisory Database