An unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 (versions before 4.0.0) allows attackers to upload files of any type to the store's media directory, which can lead to remote code execution (RCE) on misconfigured servers by uploading PHP files, enable malware hosting, facilitate stored cross-site scripting (XSS) via HTML/SVG uploads, or achieve path traversal to write files outside the intended directory.
PoC
Order Attributes for Magento 2 +2
web-vulnerability
file-upload
magento
amasty
rce
xss
2r
4t
1c
1i
updated