Web Hack List

Collected research

Shopware 5.3.3: PHP Object Instantiation to Blind XXE

A user-controlled class name reaches a PHP object instantiation in Shopware 5.3.3, and the attacker cannot call methods but can choose which class is constructed. Picking SimpleXMLElement and passing it a remote DTD turns the constructor itself into an XML external entity attack; with no output returned it is exploited blind, exfiltrating file contents through the DTD's parameter entities.

Record

Researcher
Karim El Ouerghemmi
Published by
blog.ripstech.com
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Karim El Ouerghemmi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .