CVE-2019-12799
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 6.5epss 55%
from disclosure to weapon0 days
Published on NVDJun 13
metasploitMay 9
exploitation probability
55%top 1% of all CVEs
observed exploitation
nono source reports it
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:U/UI:N
Affected products
n/a · n/a