CVE-2021-33353
CRITICALWyomind Help Desk Magento 2 <1.3.7 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-33353. PoCs published by Patrik Lantz.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Wyomind Help Desk for Magento 2, which can be leveraged to enable file uploads with dangerous extensions (e.g., 'phar') and directory traversal to achieve remote code execution (RCE). The PoC includes a detailed payload to modify backend configurations via XSS.
Description
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Wyomind Help Desk for Magento 2, which can be leveraged to enable file uploads with dangerous extensions (e.g., 'phar') and directory traversal to achieve remote code execution (RCE). The PoC includes a detailed payload to modify backend configurations via XSS.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H