Heyder Andrade
Heyder Andrade
Hey @jheysel-r7! In the last few days, I struggled to get it chained with CVE-2024-2961 by putting some pieces together, but I still haven't made real progress in obtaining RCE....
@jheysel-r7 I haven't had time to look into that last week, so I think it's worth moving forward with this module in its simplest version. I'll come back to it...
**When SRVHOST isn't correctly defined.** ``` msf6 auxiliary(gather/magento_xxe_cve_2024_34102) > set SRVHOST 0.0.0.0 SRVHOST => 0.0.0.0 msf6 auxiliary(gather/magento_xxe_cve_2024_34102) > run [*] Running module against 127.0.0.1 [*] Running automatic check ("set AutoCheck...