Improper Neutralization of Special Elements Used in a Template Engine in Shopware - CVE-2024-42356
Published: August 8, 2024 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig templates when invoking the context scope function with an attacker-controlled callable. A remote user can supply crafted Twig code to call arbitrary statically callable PHP functions or methods to execute arbitrary code.
Exploitation requires access to the administration interface, such as through mail templates or app scripts.