Логотип exploitDog
bind:CVE-2023-22731
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22731

Количество 2

Количество 2

nvd логотип

CVE-2023-22731

около 3 лет назад

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twig environment in order to exploit this vulnerability. This problem has been fixed with 6.4.18.1 with an override of the specified filters until the integration of the Sandbox extension has been finished. Users are advised to upgrade. Users of major versions 6.1, 6.2, and 6.3 may also receive this fix via a plugin.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-93cw-f5jj-x85w

около 3 лет назад

Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-22731

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twig environment in order to exploit this vulnerability. This problem has been fixed with 6.4.18.1 with an override of the specified filters until the integration of the Sandbox extension has been finished. Users are advised to upgrade. Users of major versions 6.1, 6.2, and 6.3 may also receive this fix via a plugin.

CVSS3: 9.9
5%
Низкий
около 3 лет назад
github логотип
GHSA-93cw-f5jj-x85w

Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views

CVSS3: 9.8
5%
Низкий
около 3 лет назад

Уязвимостей на страницу