承接 wubinworks/module-session-reaper-patch 相关项目开发

从需求分析到上线部署,全程专人跟进,保证项目质量与交付效率

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

wubinworks/module-session-reaper-patch

最新稳定版本:1.0.1

Composer 安装命令:

composer require wubinworks/module-session-reaper-patch

包简介

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.

README 文档

README

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.

Background

CVSS score

9.1 CRITICAL

Official information

What can the attacker damage your store?

  • Customer account takeover
  • RCE under certain conditions

Feature

  • Fixes CVE-2025-54236(a.k.a Session Reaper) vulnerability

Compatibility

No preference is used, so your Magento is still upgradable.

Behavior difference

The official fix still allows dangerous parameter to go to Setters, this patch does not allow it.

Requirements

Magento/Adobe Commerce 2.3 or 2.4

Installation

composer require wubinworks/module-session-reaper-patch

If you like this extension or this extension helped you, please share and ★star☆ this repository, it's not hard!

You may also like these extensions

Security

Feature

统计信息

  • 总下载量: 63
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 1
  • 点击次数: 0
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 1
  • Watchers: 0
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: OSL-3.0
  • 更新时间: 2025-10-19