Описание
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to FileSaver to TypeDetector, allowing malicious SVG JavaScript such as onload,
Ссылки
EPSS
Процентиль: 20%
0.00278
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.9
github
2 месяца назад
Shopware: Stored XSS via SVG file upload — no SVG sanitization
EPSS
Процентиль: 20%
0.00278
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-79