In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-28T20:22:44

Updated: 2024-08-04T12:32:14.655Z

Reserved: 2020-06-09T00:00:00

Link: CVE-2020-13971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-28T21:15:14.230

Modified: 2020-07-31T14:05:05.630

Link: CVE-2020-13971

cve-icon Redhat

No data.