home.social

#adobecommerce — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #adobecommerce, aggregated by home.social.

  1. Vulnerability in REST API allows attackers to upload executable files.

    Unrestricted file upload: all #Magento #OpenSource and #AdobeCommerce versions up to 2.4.9-alpha2

    #XSS: all versions pre-2.3.5 or custom webserver config

    #RCE via #PHP upload: #nginx 2.0.0–2.2.x (via index.php filename), any non-stock version nginx passing all .php to fastcgi, #Apache pre-2.3.5 without php_flag engine 0

    Patched: 2.4.9-alpha3+ (pre-release only)

    bleepingcomputer.com/news/secu

    sansec.io/research/magento-pol

    #Magento2