Collected research
Shopware 5.3.3: PHP Object Instantiation to Blind XXE
A user-controlled class name reaches a PHP object instantiation in Shopware 5.3.3, and the attacker cannot call methods but can choose which class is constructed. Picking SimpleXMLElement and passing it a remote DTD turns the constructor itself into an XML external entity attack; with no output returned it is exploited blind, exfiltrating file contents through the DTD's parameter entities.
Record
- Researcher
- Karim El Ouerghemmi
- Published by
- blog.ripstech.com
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Karim El Ouerghemmi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .