CVE-2020-13970

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:02

Type Values Removed Values Added
References () https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020 - Vendor Advisory () https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020 - Vendor Advisory
References () https://www.shopware.com/en/changelog/#6-2-3 - Release Notes, Vendor Advisory () https://www.shopware.com/en/changelog/#6-2-3 - Release Notes, Vendor Advisory

Information

Published : 2020-07-28 21:15

Updated : 2024-11-21 05:02


NVD link : CVE-2020-13970

Mitre link : CVE-2020-13970

CVE.ORG link : CVE-2020-13970


JSON object : View

Products Affected

shopware

  • shopware
CWE
CWE-918

Server-Side Request Forgery (SSRF)