CVE-2026-54390
CRITICALJTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-54390. PoCs published by shinthink.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-54390, a critical pre-authentication Server-Side Template Injection (SSTI) in JTL Shop 5.2.0–5.7.1. The exploit leverages Smarty template injection via contact form fields (email subject) to achieve unauthenticated remote code execution (RCE) using `file_get_contents` and other Smarty modifiers.
Description
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshell to the web root and execute arbitrary commands as the web server user.
Exploits (1)
This repository contains a functional exploit for CVE-2026-54390, a critical pre-authentication Server-Side Template Injection (SSTI) in JTL Shop 5.2.0–5.7.1. The exploit leverages Smarty template injection via contact form fields (email subject) to achieve unauthenticated remote code execution (RCE) using `file_get_contents` and other Smarty modifiers.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H