Server-side request forgery (SSRF) In shopware/shopware
Description
Shopware vulnerable to SSRF Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.2.3 | ||
packagist | 6.2.3 | ||
packagist | 6.2.3 |
Aliases
1. 2. 3. 4.
References
1. 2.