PT-2026-48882 · Amasty · Order Attributes

·

CVE-2026-53787

·

Published

2026-06-12

·

Updated

2026-07-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amasty Order Attributes for Magento 2 versions prior to 4.0.0
Description An unauthenticated arbitrary file upload issue allows attackers to write files of any type or name to the store's media directory. This occurs because the upload endpoint lacks authentication, session validation, and cart context. This can lead to remote code execution if the media directory permits PHP execution. Additionally, it enables malware hosting, stored cross-site scripting (XSS)—where malicious scripts are permanently stored on the server—via HTML or SVG uploads, and path traversal to write files outside the intended directory.
Recommendations Update to version 4.0.0 or later.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53787

Affected Products

Order Attributes