Shopware Insecure Deserialization Vulnerability
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 31, 2023
Description
Published by the National Vulnerability Database
Jun 13, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 31, 2023
Last updated
Jul 31, 2023
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
References