Vulnerabilities > CVE-2020-13970 - Server-Side Request Forgery (SSRF) vulnerability in Shopware

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
shopware
CWE-918

Summary

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

Vulnerable Configurations

Part Description Count
Application
Shopware
161

Common Weakness Enumeration (CWE)