CVE-2019-12799
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 54.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 54.68% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- shopware/shopware
- Source
- cve@mitre.org
References
- https://github.com/rapid7/metasploit-framework/pull/11828Issue Tracking, Patch, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/11828Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.