Source |
CVE Liste |
Identifiant |
8328595 |
Date de publication |
2023-04-17 11:15:42 (vue: 2023-04-17 13:07:13) |
Titre |
CVE-2023-2017 |
Texte |
Injection de modèle côté serveur (SSTI) dans Shopware 6 ( |
Notes |
|
Envoyé |
Oui |
Condensat |
2017 2023 22731 `shopware access adapter advised affecting allows any arbitrary are array attackers both bypass call callables checks code/commands core cve environment execute extension framework fully function github injection issue names php qualified rc1 rc4 referencing remote repositories resolve sandbox securityextension` server shopware shopware/core shopware/platform side ssti strings supplied template thus twig upgrade usage users validation when without |
Tags |
|
Stories |
|
Move |
|