Lucene search

K
osvGoogleOSV:GHSA-RF8F-HQJV-986P
HistoryMay 24, 2022 - 4:48 p.m.

Shopware Insecure Deserialization Vulnerability

2022-05-2416:48:00
Google
osv.dev
1

7 High

AI Score

Confidence

High

0.333 Low

EPSS

Percentile

97.1%

In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.

7 High

AI Score

Confidence

High

0.333 Low

EPSS

Percentile

97.1%