CVE-2020-13970

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-07-28 21:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-13970

Mitre link : CVE-2020-13970

CVE.ORG link : CVE-2020-13970


JSON object : View

Products Affected

shopware

  • shopware
CWE
CWE-918

Server-Side Request Forgery (SSRF)