CVE-2017-18357

6.5MEDIUM

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via

Veröffentlicht: 1/15/2019Aktualisiert: 11/21/2024

Beschreibung

Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

KI-AnalyseKI-gestützt

Betroffene Produkte

shopwareshopware

Verfügbare Exploits (1)

Referenzen