Medium severity6.5GHSA Advisory· Published Jan 15, 2019· Updated Jun 17, 2026
CVE-2017-18357
CVE-2017-18357
Description
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/shopwarePackagist | < 5.3.4 | 5.3.4 |
Affected products
3Patches
Vulnerability mechanics
References
6- blog.ripstech.com/2017/shopware-php-object-instantiation-to-blind-xxe/nvdExploitThird Party Advisory
- demo.ripstech.com/projects/shopware_5.3.3nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-6m27-7cqj-2mxwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-18357ghsaADVISORY
- packetstormsecurity.com/files/152995/Shopware-createInstanceFromNamedArguments-PHP-Object-Instantiation.htmlnvdWEB
- blog.ripstech.com/2017/shopware-php-object-instantiation-to-blind-xxeghsaWEB
News mentions
0No linked articles in our index yet.