First published: Sat Mar 29 2025(Updated: )
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
Affected Software | Affected Version | How to fix |
---|---|---|
composer/shopxo/shopxo | <=6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-p736-g6pg-hjhw is classified as high due to the potential for unauthorized access and data exposure.
To fix GHSA-p736-g6pg-hjhw, update ShopXO to a version beyond 6.4.0 where the SSRF vulnerability is patched.
Server-Side Request Forgery in GHSA-p736-g6pg-hjhw refers to an attack where an attacker can send requests from the server to internal or external resources.
ShopXO versions up to and including 6.4.0 are affected by GHSA-p736-g6pg-hjhw.
Yes, GHSA-p736-g6pg-hjhw can potentially lead to data breaches if exploited, as it allows attackers to interact with vulnerable endpoints.