First published: Tue Jul 28 2020(Updated: )
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/shopware/platform | <6.2.3 | 6.2.3 |
Shopware Shopware | <6.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13971 is a vulnerability in Shopware before version 6.2.3 which allows authenticated users to upload SVG images containing JavaScript, leading to Persistent XSS.
CVE-2020-13971 affects Shopware versions prior to 6.2.3.
The severity of CVE-2020-13971 is medium, with a CVSS score of 5.4.
To fix CVE-2020-13971, update Shopware to version 6.2.3 or later.
You can find more information about CVE-2020-13971 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-13971), [Shopware Security Updates](https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020), [Shopware Changelog](https://www.shopware.com/en/changelog/#6-2-3).