← Back to CVE List

CVE-2020-13970

Published: 2020-07-28T21:15Z
Last Modified: 2024-11-21T05:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt