CVE-2019-12799
13.06.2019, 20:29
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.Enginsight
Vendor | Product | Version |
---|---|---|
shopware | shopware | 𝑥 ≤ 5.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration