Magento Patches Critical SQL Injection and RCE Vulnerabilities
#1
Quote:Magento patched 37 vulnerabilities on Thursday, including a host of critical flaws in the e-commerce platform that could have let attackers perform a range of malicious activities, such as take over a site and create new admin accounts.
 
The most serious of the bugs is a remote code-execution (RCE) vulnerability that could allow an authenticated user, with limited permissions, to create specially crafted newsletters and email templates that can be used to execute arbitrary code on targeted systems. The vulnerability has a CVSS score of 9.8 and impacts Magento versions 2.1 prior to 2.1.17, Magento 2.2 prior to 2.2.8 and Magento 2.3 prior to 2.3.1.

A second critical bug patched by Magento is an unauthenticated SQL injection vulnerability that could allow an attacker exploiting the flaw to “read from the [Magento] database, [and] extract admin sessions or password hashes and use them to access the backend,” according to Ambionics Security. This would allow site takeover with the stolen credentials.

SOURCE: https://threatpost.com/magento-xss-csrf-...es/143274/
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
Good this has been fixed, especially now that credentials attacks are becoming more popular and sophisticated, which could use flaws to perform malicious activities and access critical information.
[-] The following 1 user says Thank You to Deep900 for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Spam 101: what is spam, and how to defea...
It feels as if spa...harlan4096 — 07:51
Vivaldi 7.1 Build 3570.42
Vivaldi 7.1 Build ...harlan4096 — 07:48
Emsisoft Anti-Malware 2025.2.0.12659
Changes in 2025.2....harlan4096 — 11:00
AVG 25.1.9816
AVG 25.1.9816: ...harlan4096 — 10:59
Avast 25.1.9816
Avast 25.1.9816: ...harlan4096 — 10:58

[-]
Birthdays
Today's Birthdays
avatar (40)oecmecodo
avatar (39)ShakitaSmobe
Upcoming Birthdays
avatar (46)hapedDow
avatar (45)komriwat
avatar (37)showercurtains
avatar (48)PeterWhink
avatar (49)neuthrusBub
avatar (48)tsorenHievy
avatar (45)myhotseeve
avatar (45)Edwinmub
avatar (45)dimaWeami
avatar (40)svoyaEnuct
avatar (38)TranoTymn
avatar (38)MezirLal
avatar (49)listfquoto
avatar (45)dima6sarPrave
avatar (37)Michaelaburi
avatar (45)dpascoal
avatar (50)Ronaldduh
avatar (38)legalgauch
avatar (40)yposegij
avatar (43)Baihu
avatar (26)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>