CVE-2026-103831:TrueLayer Magento 2 插件中的 Psr16CacheAdapter 组件存在不安全的反序列化漏洞。该漏洞源于在从缓存中检索数据时,直接使用了 PHP 原生的 函数,且未对允许反序列化的类进行任何限制。如果攻击者已经能够将篡改后的数据写入 Magento 所使用的缓存后端(例如 Redis 或 Memcached),则可以注入特制的 PHP 对象并触发其反序列化,进而利用应用程序环境中可用的“gadget 链”实现任意代码执行。因此,成功利用此漏洞的前提条件是攻击者具
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TrueLayer | TrueLayer Magento 2 Plugin | versions 2.4.0 through 2.4.2. | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet