High severity8.8NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026
CVE-2021-37711
CVE-2021-37711
Description
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | < 6.4.3.1 | 6.4.3.1 |
shopware/corePackagist | < 6.4.3.1 | 6.4.3.1 |
Affected products
4- ghsa-coords2 versions
< 6.4.3.1+ 1 more
- (no CPE)range: < 6.4.3.1
- (no CPE)range: < 6.4.3.1
- shopware/platformv5Range: <= 6.4.3.0
Patches
Vulnerability mechanics
References
4- github.com/shopware/platform/commit/b9f330e652b743dd2374c02bbe68f28b59a3f502nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gcvv-gq92-x94rghsaADVISORY
- github.com/shopware/platform/security/advisories/GHSA-gcvv-gq92-x94rnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37711ghsaADVISORY
News mentions
0No linked articles in our index yet.