Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
Vulnerability Description
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
CWE-1336
Vulnerability Title
Shopware 安全漏洞
Vulnerability Description
Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware 6.6.5.1和6.5.8.13及之前版本存在安全漏洞,该漏洞源于漏洞源于其新的Twig标签,该标签用于静默化弃用消息,但由于参数没有正确转义,从而允许执行代码。
CVSS Information
N/A
Vulnerability Type
N/A