Blog post

Magento 2.3.1: Unauthenticated Stored XSS to RCE

Simon Scannell photo

Simon Scannell

Vulnerability Researcher

This blog post shows how the combination of a HTML sanitizer bug and a Phar Deserialization in the popular eCommerce solution Magento <=2.3.1 lead to a high severe exploit chain. This cha...