{"id":"CVE-2019-12799","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-12799","summary":"Shopware Insecure Deserialization Vulnerability","details":"In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.","published":"2022-05-24T16:48:00Z","modified":"2024-02-16T08:16:39.454275Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/shopware","fixedVersion":null}],"fix":{"url":"https://github.com/rapid7/metasploit-framework/pull/11828","label":"rapid7/metasploit-framework#11828"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12799"},{"type":"WEB","url":"https://github.com/rapid7/metasploit-framework/pull/11828"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6m27-7cqj-2mxw"},{"type":"PACKAGE","url":"https://github.com/shopware5/shopware"},{"type":"WEB","url":"https://web.archive.org/web/20171112153855/https://blog.ripstech.com/2017/shopware-php-object-instantiation-to-blind-xxe"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:16:39.454275Z"}}