Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-24087 — Proof-of-concept exploit for CVE-2022-24086 and CVE-2022-24087, demonstrating pre-authentication remote code execution in Magento/Adobe Commerce via crafted payloads bypassing input validation. | Kitploit
Tools/GitHubGitHub/neimar47574/cve-2022-24087
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubneimar47574/cve-2022-24087

CVE-2022-24087

Proof-of-concept exploit for CVE-2022-24086 and CVE-2022-24087, demonstrating pre-authentication remote code execution in Magento/Adobe Commerce via crafted payloads bypassing input validation.

View Repository
1114 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-24087-RCE and CVE-2022-24086-RCE

CVE description

CVE-2022-24086 and CVE-2022-24087 - improper Input Validation vulnerability in contact form Magento Open Source and Adobe Commerce - has received a CVSS score of 9.8 out of 10, it is classified as a pre-authentication issue which means that it could be exploited without credentials.

Vulnerabile versions:

Magento Open Source / Adobe Commerce - 2.3.3-p1 - 2.3.4

Magento Open Source / Adobe Commerce - 2.3.4-p2 - 2.4.2-p2

Magento Open Source / Adobe Commerce - 2.4.3 - 2.4.3-p1

Analysis

CVE-2022-24086 was a critical, zero-day security vulnerability that affected Magento shops. The vulnerability was reported in limited attacks. Another flaw, CVE-2022-24087, has the same severity level and similar vector of attack.

After some research I found no legit and working PoC to demonstrate a severity of that flaw from Adobe and I decided to make my own. Reverse engineering of official and unofficial patches I found that in /app/code/Magento/Email/Model/Template/Filter.php input was not properly cleared and inability for the platform to recognize a combination of character types during the time of form validation, harmful sequences are allowed to wreak havoc unabated, allowing to bypass input validation methods normally used to sanitize unwanted input types. It opens up the ability for SQL and PHP object injection attacks within Magento, which can add unwanted database entries or enable remote code execution.

Some parts of added code in official patches (MDVA-43395) that lead us to PoC:

CVE-2022-24086 PoC and CVE-2022-24087 PoC

What we need to do is to craft some sophisticated payload to POST:

Download Tool