Executive brief
JTL Shop, a popular e-commerce platform, contains a critical security flaw in its email template system. An unauthenticated attacker can exploit this to steal sensitive information like database passwords and encryption keys. In many versions, this also allows the attacker to take full control of the web server, potentially leading to data theft, site defacement, or the installation of malicious software.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in JTL Shop due to improper neutralization of user-supplied input passed to the Smarty template engine, specifically within email subject lines. Unauthenticated attackers can inject malicious template syntax to read sensitive server-side variables, including the BLOWFISH_KEY and database credentials. In versions 5.4.0 through 5.7.1, the risk is elevated to Remote Code Execution (RCE) because the application registers Smarty modifiers such as 'unserialize' and 'file_get_contents', which can be abused to write webshells to the web root. The vulnerability has been patched in versions 5.5.4, 5.6.2, and 5.7.2, with back-patches available for older 5.x branches.
Affected products
- JTL Software JTL Shop 5.2.0 - 5.7.1
Timeline
- 2022-12-19: other: Vulnerability introduced in version 5.2.0
- 2026-06-05: other: Vulnerability reported to vendor by Sansec
- 2026-06-17: patched: Vendor releases versions 5.5.4, 5.6.2, and 5.7.2
- 2026-06-18: advisory: Public disclosure and CVE assignment