Backdoor found in popular ecommerce components
sansec.io
sansec.io
> Magesolution (MGS) did not respond, but the backdoored packages can still be downloaded from their site as of Apr 30th.
> Tigren denies to have been hacked, but the backdoored packages are still available on their site as of Apr 30th.
> Meetanshi claims that their software has not been tampered with, but confirmed that their server got hacked.
This is just as likely to be an RCE as it is to be a backdoor. Calling `include` on a file the user can write to is just asking for it. This has been a known footgun for decades.