Логотип exploitDog
bind:CVE-2020-13971
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13971

Количество 2

Количество 2

nvd логотип

CVE-2020-13971

больше 5 лет назад

In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fxf3-wx3c-76pf

больше 3 лет назад

Shopware vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-13971

In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

CVSS3: 5.4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-fxf3-wx3c-76pf

Shopware vulnerable to Cross-site Scripting

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу