Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-28T20:24:16

Updated: 2024-08-04T12:32:14.608Z

Reserved: 2020-06-09T00:00:00

Link: CVE-2020-13970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-28T21:15:14.167

Modified: 2020-07-31T14:03:59.127

Link: CVE-2020-13970

cve-icon Redhat

No data.