Improper Neutralization of Special Elements Used in a Template Engine in Shopware - CVE-2024-42356

 

Improper Neutralization of Special Elements Used in a Template Engine in Shopware - CVE-2024-42356

Published: August 8, 2024 / Updated: May 20, 2026


Vulnerability identifier: #VU131896
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-42356
CWE-ID: CWE-1336
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Shopware
Affected software:
Shopware

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig templates when invoking the context scope function with an attacker-controlled callable. A remote user can supply crafted Twig code to call arbitrary statically callable PHP functions or methods to execute arbitrary code.

Exploitation requires access to the administration interface, such as through mail templates or app scripts.


How to mitigate CVE-2024-42356

Install security update from vendor's website.

Sources