{"api_version":"1","generated_at":"2026-07-24T19:41:15+00:00","cve":"CVE-2020-13970","urls":{"html":"https://cve.report/CVE-2020-13970","api":"https://cve.report/api/cve/CVE-2020-13970.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-13970","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-13970"},"summary":{"title":"CVE-2020-13970","description":"Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its \"Mediabrowser upload by URL\" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-07-28 21:15:00","updated_at":"2020-07-31 14:03:00"},"problem_types":["CWE-918"],"metrics":[],"references":[{"url":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020","name":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Update 07/2020","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.shopware.com/en/changelog/#6-2-3","name":"https://www.shopware.com/en/changelog/#6-2-3","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"Shopware Changelog Shopware 6","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-13970","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13970","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"13970","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shopware","cpe5":"shopware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13970","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shopware","cpe5":"shopware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-13970","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its \"Mediabrowser upload by URL\" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.shopware.com/en/changelog/#6-2-3","url":"https://www.shopware.com/en/changelog/#6-2-3"},{"refsource":"CONFIRM","name":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020","url":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020"}]}},"nvd":{"publishedDate":"2020-07-28 21:15:00","lastModifiedDate":"2020-07-31 14:03:00","problem_types":["CWE-918"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*","versionEndExcluding":"6.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"13970","Ordinal":"175196","Title":"CVE-2020-13970","CVE":"CVE-2020-13970","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"13970","Ordinal":"1","NoteData":"Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its \"Mediabrowser upload by URL\" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"13970","Ordinal":"2","NoteData":"2020-07-28","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"13970","Ordinal":"3","NoteData":"2020-07-28","Type":"Other","Title":"Modified"}]}}}