CVEs Blog | G5 Cyber Security

CVE-2020-13970 – Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSR

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its “Mediabrowser upload by URL” feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13970

Reference (s):

Exit mobile version