CVE detail
CVE-2019-12799 — CVE-2019-12799
Published 2019-06-13 · Modified 2026-06-17 · Vendor shopware · Product shopware · Source nvd
HIGH
severity
CVSS-derived band
0.5468
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References