Medium severity5.4NVD Advisory· Published Jul 28, 2020· Updated Jun 17, 2026
CVE-2020-13971
CVE-2020-13971
Description
In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.2.3 | 6.2.3 |
Affected products
3- Shopware/Shopwaredescription
Patches
Vulnerability mechanics
References
4- docs.shopware.com/en/shopware-6-en/security-updates/security-update-07-2020nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-fxf3-wx3c-76pfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13971ghsaADVISORY
- www.shopware.com/en/changelog/nvdRelease NotesVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.