CVE-2019-12799
HIGHShopware 5.3.0-5.6.x - Remote Code Execution via PHP Object Instantiation Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-12799.
PoCs published by Karim Ouerghemmi, mr_me <[email protected]>, including Metasploit module exploits/multi/http/shopware_createinstancefromnamedarguments_rce.
AI-analyzed exploit summary This Metasploit module exploits a PHP object instantiation vulnerability in Shopware's `createInstanceFromNamedArguments` function, leading to remote code execution via deserialization of a malicious PHAR file. It includes authentication, CSRF token leakage, PHAR generation, and payload delivery.
Description
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
Exploits (1)
This Metasploit module exploits a PHP object instantiation vulnerability in Shopware's `createInstanceFromNamedArguments` function, leading to remote code execution via deserialization of a malicious PHAR file. It includes authentication, CSRF token leakage, PHAR generation, and payload delivery.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H