HIGH8.8
GHSA-5vmg-x99g-396q
Shopware vulnerable to SSRF
Quick fix
GHSA-5vmg-x99g-396q — shopware/platform: upgrade to the fixed version with the command below.
composer require shopware/platform:^6.2.3Details
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/shopware/platform
Introduced in:
0Fixed in: 6.2.3Fix
composer require shopware/platform:^6.2.3