CVE-2017-18357

MEDIUM

Shopware < 5.3.4 - PHP Object Instantiation and XXE via ProductStream Controller

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2017-18357. PoCs published by Metasploit, Karim Ouerghemmi, mr_me <[email protected]>, including Metasploit module exploits/multi/http/shopware_createinstancefromnamedarguments_rce.

AI-analyzed exploit summary This Metasploit module exploits a PHP object instantiation vulnerability in Shopware via the `createInstanceFromNamedArguments` function, leading to remote code execution. It leverages deserialization via a crafted PHAR file to write a webshell.

Description

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/46915

This Metasploit module exploits a PHP object instantiation vulnerability in Shopware via the `createInstanceFromNamedArguments` function, leading to remote code execution. It leverages deserialization via a crafted PHAR file to write a webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Shopware (tested on 5.3, 5.4, 5.5, 5.6)
Auth required
Prerequisites: Authenticated backend access · Valid credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Karim Ouerghemmi, mr_me <[email protected]> · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/shopware_createinstancefromnamedarguments_rce.rb

This Metasploit module exploits a PHP object instantiation vulnerability in Shopware's `createInstanceFromNamedArguments` function, leading to remote code execution via deserialization of a malicious PHAR file. It requires backend authentication and targets Shopware versions 5.3-5.6.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Shopware 5.3-5.6
Auth required
Prerequisites: Valid backend credentials · Access to the Shopware backend
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 6.5
EPSS 0.5729
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-610
Status published
Products (2)
shopware/shopware < 5.3.4
shopware/shopware 0 - 5.3.4Packagist
Published Jan 15, 2019
Tracked Since Feb 18, 2026