CVE-2020-13970

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
28/07/2020
Last modified:
31/07/2020

Description

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:* 6.2.3 (excluding)