ZeroHour

CVE-2020-13970

CVSS 3.1
8.8 high
EPSS
1%p68
Published
()
Modified
Description

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

Vendors
shopware
Products
shopware
Ecosystems
E-commerce
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.