vendor:
Magento
by:
agix (discovered by NETANEL RUBIN)
9.8
CVSS
CRITICAL
Arbitrary unserialize
CWE
Product Name: Magento
Affected Version From: < 2.0.6
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2016-4010
CPE:
Platforms Tested:
2016
CVE-2016-4010 Magento unauthenticated arbitrary unserialize -> arbitrary write file
This exploit allows an attacker to perform arbitrary unserialize and arbitrary write file operations in Magento versions below 2.0.6. By exploiting a vulnerability in the Magento framework, an attacker can execute arbitrary code and potentially take control of the system.
Mitigation:
Upgrade to Magento version 2.0.6 or higher. Apply any available patches or security updates provided by the vendor.