Magento – RCE & Local File Read...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

I regularly search for vulnerabilities on big services that allow it and have a Bug Bounty program. Here is a second paper which covers two vulnerabilities I discovered on Magento, a big ecommerce CMS that’s now part of Adobe Experience Cloud. These vulnerabilities have been responsibly disclosed to Magento team, and patched for Magento 2.3.0, 2.2.7 and 2.1.16. Both of vulnerabilities need low privileges admin account, usually given to Marketing users : The first vulnerability is a command execution using path traversal, and requires the user to be able to create products The second vulnerability is a local file read, and requires the user to be able to create email templates Here are the details ! ### Command Execution in Product Creation Magento has its own way to define the layout of a product, into the Design tab of the Product creation system. It’s format is XML-based and follows a syntax documented by Magento themselves. The full documentation is here :...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息