Get auth Magento RCE using deserialized PHAR files

Опубликовано: 31 Май 2026
на канале: Pentest-Tools
1,112
5

🛡 Back in August 2019, I reported a security vulnerability in Magento affecting versions 2.3.2, 2.3.3, and 2.3.4 using the HackerOne bug bounty platform.

The bug impacted some installations of Magento and it allowed us to gain Remote Code Execution based on the way PHAR files are deserialized and by abusing Magento’s Protocol Directives.

The vulnerability was patched by Adobe on April 28, 2020, but unpatched deployments are still vulnerable to this risk with high business impact.

⚙️ Read the full technical walk-through and learn how users with any privilege level can exploit this vulnerability ➡️ https://pentest-tools.com/blog/magent...

______________
💡 See ALL OUR TOOLS: https://pentest-tools.com/alltools
@ us on Twitter:   / pentesttoolscom  
Join 46k+ offensive security specialists on LinkedIn:   / pentesttools  

#PenetrationTesting #Pentesting #EthicalHacking #PentestToolsCom
______________
WHAT IS Pentest-Tools.com?

Use the Pentest-Tools.com platform to quickly detect and report vulnerabilities in websites and network infrastructures!

✔ 20+ tightly integrated penetration testing and ethical hacking tools for easier, faster, and more effective engagements
✔ Built for pentesters, sysadmins, web devs, MSPs, business owners, and other professionals seeking to automate and save time
✔ Painless vulnerability management: add manual findings, change risk levels, delete obsolete targets, create and export customizable reports (complete with vulnerability information and remediation suggestions)
✔ Instant overview of all open ports, services, and running software from all your targets in a central, unified view (Attack Surface)
✔ Comprehensive scanning options: scheduled scans, robust API, internal network scanning through VPN agent, scan multiple targets at the same time
✔ Flexible subscription: choose monthly billing and you can cancel anytime. Alternatively, choose the yearly plan and get a 15% discount!

"Pentest-Tools is great for streamlining any security engagement" - Tavis D., Security Engineering Manager

"A superb toolbox, not the usual easy online toy" - Mauro G., DevOps Specialist

“Pentest-Tools.com is the Swiss Army Knife of scanning tools”
Mark D., Apple Certified Support Professional

See how our customers use the platform:
https://www.g2.com/products/pentest-t...