CVE-2026-53787
CRITICAL NUCLEIAmasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-53787. PoCs published by webshellseo8. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository claims to contain a PoC for CVE-2026-53787 but lacks actual exploit code, instead referencing an external Python script and promoting a Telegram channel. No technical details or code are provided.
Description
Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authentication, session validation, or cart context. Attackers can upload PHP files to achieve remote code execution on servers where the media directory permits PHP execution, or alternatively enable malware hosting, stored cross-site scripting via HTML or SVG uploads, and path traversal to write files outside the intended upload directory.
Exploits (1)
The repository claims to contain a PoC for CVE-2026-53787 but lacks actual exploit code, instead referencing an external Python script and promoting a Telegram channel. No technical details or code are provided.
Nuclei Templates (1)
http.component:"Magento"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H