wubinworks/module-session-reaper-patch
最新稳定版本:1.0.1
Composer 安装命令:
composer require wubinworks/module-session-reaper-patch
包简介
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
关键字:
README 文档
README
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
Background
CVSS score
9.1 CRITICAL
Official information
What can the attacker damage your store?
- Customer account takeover
- RCE under certain conditions
Feature
- Fixes CVE-2025-54236(a.k.a Session Reaper) vulnerability
Compatibility
No preference is used, so your Magento is still upgradable.
Behavior difference
The official fix still allows dangerous parameter to go to Setters, this patch does not allow it.
Requirements
Magento/Adobe Commerce 2.3 or 2.4
Installation
composer require wubinworks/module-session-reaper-patch
♥
If you like this extension or this extension helped you, please share and ★star☆ this repository, it's not hard!
You may also like these extensions
Security
- Magento 2 Cosmic Sting Patch for CVE-2024-34102
- Magento 2 Trojan Orders Patch for CVE-2022-24086, CVE-2022-24087
- Magento 2 Enhanced XML Security
- Magento 2 Encryption Key Manager CLI
- Magento 2 JWT Authentication Patch
Feature
统计信息
- 总下载量: 63
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 1
- 点击次数: 0
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: OSL-3.0
- 更新时间: 2025-10-19