Логотип exploitDog
bind:CVE-2022-24871
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24871

Количество 2

Количество 2

nvd логотип

CVE-2022-24871

почти 4 года назад

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-7gm7-8q8v-9gf2

почти 4 года назад

Server-Side Request Forgery (SSRF) in Shopware

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24871

Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-7gm7-8q8v-9gf2

Server-Side Request Forgery (SSRF) in Shopware

CVSS3: 7.2
0%
Низкий
почти 4 года назад

Уязвимостей на страницу