[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Magento 2.4.0 / 2.3.5p1 (and earlier) Arbitrary Code Execution 0day Exploit

[ 0Day-ID-36026 ]
Full title
Magento 2.4.0 / 2.3.5p1 (and earlier) Arbitrary Code Execution 0day Exploit [ Highlight ]
Highlight - is paid service, that can help to get more visitors to your material.

Price: 10
Date add
Category
Platform
Verified
Price
 
0.032 BTC

 
3 000 USD
Risk
[
Security Risk Critical
]
Rel. releases
Description
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.
Affected ver
2.4.0 and 2.3.5p1 (and earlier)
Tested on
Magento: 2.4.0 with PHP 7.3 and Ubuntu 18.04.
Magento: 2.4.0 with PHP 7.4 and Ubuntu 20.04
Solution
N/A
CVE
CVE-2020-24407
Prooves Information
Video proof
Other Information
Abuses
0
Comments
2
Views
7 949
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
Please login or register to buy exploit.
OR
Buy incognito
0
0
Verified by 0day Admin
Verified by 0day Admin
This material is checked by Administration and absolutely workable.
Learn more about    GOLD:
0day.today Gold is the currency of 0day.today project and is denoted on this site as such image: . It used for paying for the services, buying exploits, earning money, etc
We accept:
BitCoin (BTC)
You can pay us via BTC
LiteCoin (LTC)
You can pay us via LTC
Ethereum (ETH)
You can pay us via ETH

Author
BL
29
Exploits
1
Readers
0
[ Comments: 2 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.
02-03-2022, 12:06
what about the latest exploit?
Administrator
02-03-2022, 13:48
We have last version to 0day.today/0day
------------------------------
0day.today Administrator

Login or register to leave comments