CVE-2017-18357
15.01.2019, 16:29
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.Enginsight
Vendor | Product | Version |
---|---|---|
shopware | shopware | 𝑥 < 5.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References