← back
CVE-2016-4010

CVE-2016-4010

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 93%
from disclosure to weapon0 days
Published on NVDJan 23
1st PoCMay 18
metasploitMay 17
exploitation probability
93%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.