Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7336-ghhp-f2qj

Опубликовано: 21 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Shopware Remote Code Execution Vulnerability

Under certain circumstances, it’s possible to execute an unauthorized foreign code in Shopware in versions prior to 5.2.16. One possible threat is if a template that doesn’t derive from the Shopware standard has been completely copied. Themes or plugins that execute or overwrite the following template code are vulnerable.

  • Affected file: emotion.tpl

Path template file "Emotion template": templates / _default / frontend / forms / elements.tpl Path template file "Responsive template": themes/Frontend/Bare/frontend/forms/elements.tpl

The complete line beginning with: {eval var=$sSupport.sFields[$sKey]... should be exchanged with the following:

{$sSupport.sFields[$sKey]|replace:'{literal}':''|replace:'{/literal}':''|replace:'%*%':"{s name='RequiredField' namespace='frontend/register/index'}{/s}"}

Пакеты

Наименование

shopware/shopware

composer
Затронутые версииВерсия исправления

= 5.2.15

5.2.16

9.8 Critical

CVSS3

Дефекты

CWE-74

9.8 Critical

CVSS3

Дефекты

CWE-74