In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3854 In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
Github GHSA Github GHSA GHSA-fxf3-wx3c-76pf Shopware vulnerable to Cross-site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T12:32:14.655Z

Reserved: 2020-06-09T00:00:00

Link: CVE-2020-13971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-28T21:15:14.230

Modified: 2024-11-21T05:02:16.100

Link: CVE-2020-13971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.