VDB
Sign up
HIGH8.8

GHSA-5vmg-x99g-396q

Shopware vulnerable to SSRF

Quick fix

GHSA-5vmg-x99g-396q — shopware/platform: upgrade to the fixed version with the command below.

composer require shopware/platform:^6.2.3

Details

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shopware/platform
Introduced in: 0Fixed in: 6.2.3
Fixcomposer require shopware/platform:^6.2.3

References