CVE-2017-18357
MEDIUMShopware < 5.3.4 - PHP Object Instantiation and XXE via ProductStream Controller
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-18357.
PoCs published by Metasploit, Karim Ouerghemmi, mr_me <[email protected]>, including Metasploit module exploits/multi/http/shopware_createinstancefromnamedarguments_rce.
AI-analyzed exploit summary This Metasploit module exploits a PHP object instantiation vulnerability in Shopware via the `createInstanceFromNamedArguments` function, leading to remote code execution. It leverages deserialization via a crafted PHAR file to write a webshell.
Description
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.
Exploits (2)
This Metasploit module exploits a PHP object instantiation vulnerability in Shopware via the `createInstanceFromNamedArguments` function, leading to remote code execution. It leverages deserialization via a crafted PHAR file to write a webshell.
This Metasploit module exploits a PHP object instantiation vulnerability in Shopware's `createInstanceFromNamedArguments` function, leading to remote code execution via deserialization of a malicious PHAR file. It requires backend authentication and targets Shopware versions 5.3-5.6.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N