A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.
References
| Link | Resource |
|---|---|
| https://github.com/capture0x/Magento-ver.-2.4.6 | Exploit |
| https://packetstormsecurity.com/files/175801/FireBear-Improved-Import-And-Export-3.8.6-XSLT-Server-Side-Injection.html | Third Party Advisory VDB Entry |
| https://github.com/capture0x/Magento-ver.-2.4.6 | Exploit |
| https://packetstormsecurity.com/files/175801/FireBear-Improved-Import-And-Export-3.8.6-XSLT-Server-Side-Injection.html | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2024-02-16 02:15
Updated : 2025-03-26 14:15
NVD link : CVE-2024-25413
Mitre link : CVE-2024-25413
CVE.ORG link : CVE-2024-25413
JSON object : View
Products Affected
firebearstudio
- improved_import_\&_export
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
