Improper Neutralization of Special Elements Used in a Template Engine in Shopware - CVE-2024-42355
Published: August 8, 2024 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in the Twig sw_silent_feature_call tag when processing a feature flag name parameter. A remote user can supply a crafted parameter value to execute arbitrary code.