CVE-2020-13970

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
Configurations

Configuration 1

cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*

Information

Published : 2020-07-28 09:15

Updated : 2020-07-31 02:03


NVD link : CVE-2020-13970

Mitre link : CVE-2020-13970

Products Affected
No products.
CWE
CWE-918

Server-Side Request Forgery (SSRF)