CVE-2017-18357

MEDIUM

Shopware < 5.3.4 - XXE

Title source: rule

Description

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

Exploits (2)

metasploit WORKING POC EXCELLENT
by Karim Ouerghemmi, mr_me <[email protected]> · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/shopware_createinstancefromnamedarguments_rce.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/46915

Scores

CVSS v3 6.5
EPSS 0.5729
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-610
Status published

Affected Products (2)

shopware/shopware < 5.3.4
shopware/shopware < 5.3.4Packagist

Timeline

Published Jan 15, 2019
Tracked Since Feb 18, 2026