RSSAmplifier

Posts - Scott Robinson · @ssxio · Mar 30, 2026

Blocking SessionReaper and PolyShell File Access with Fastly on Magento/Adobe Commerce

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

If you’ve been keeping an eye on the Magento security space recently, you’ll have seen the research from Sansec around SessionReaper exploitation and the more recent PolyShell - both of which use the media/custom_options/ directory as a vector for uploading and executing malicious PHP files. The SessionReaper attack targets session data to extract customer and admin credentials, and the PolyShell…

Read on dor.ky

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.