Shopware 5.3.3: PHP Object...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

[Shopware](https://shopware.com/)is a popular e-commerce software. It is based on PHP using technologies like Symfony 2, Doctrine and the Zend Framework. The code base of its open source community edition encompasses over 690,000 lines of code which we scanned for security vulnerabilities with our RIPS static code analyzer. The analysis of this complex code base took roughly 4 minutes. RIPS discovered two vulnerabilities: a PHP object instantiation and a SQL injection which we disclosed to the vendor and were fixed in [version 5.3.4](http://community.shopware.com/_detail_2035.html). In this blog post we investigate the rare object instantiation vulnerability. We describe how it can occur and how it can be exploited by an attacker in order to retrieve arbitrary files from the server. ### Who is affected Installations with following requirements are affected by this vulnerabilities: * Shopware version <= 5.3.3 and >= 5.1 ### Impact - What can an attacker do In order to exploit the...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息