shopware/core is vulnerable to Path Traversal
80
High Risk
shopware/core accepted direct writes to media.fileExtension without applying the same configured extension allowlist used for media uploads. An authenticated Administration user with the media:update privilege can set a crafted extension containing path elements and write files outside the intended media directory. In affected configurations this can place executable PHP on the server and lead to remote code execution. The fix validates public and private media extensions on every write and rejects illegal values with MEDIA_ILLEGAL_FILE_EXTENSION.
You are affected if you are using a version that falls within the vulnerable range and Administration users or integrations have the media:update privilege.
shopware/core is vulnerable to Path Traversal in versions 6.7.1.0 - 6.7.13.0.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant