Libraries tagged by sessionreaper

deployecommerce/module-prevent-customer-address-file-upload

9 Favers
5197 Downloads

A Magento2 extension that prevents file uploads to the /customer/address_file/upload endpoint.

Go to Download


wubinworks/module-session-reaper-patch

3 Favers
590 Downloads

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.

Go to Download


qoliber/magento-open-source-security

1 Favers
84 Downloads

Magento 2 security modules for Qoliber open source patches and fixes.

Go to Download