VYPR

Order Attributes

by Amasty

CVEs (1)

  • CVE-2026-53787CriJun 12, 2026
    risk 0.64cvss 9.8epss

    Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint…