Magento Patches Critical SQL Injection and RCE Vulnerabilities
#1
Quote:Magento patched 37 vulnerabilities on Thursday, including a host of critical flaws in the e-commerce platform that could have let attackers perform a range of malicious activities, such as take over a site and create new admin accounts.
 
The most serious of the bugs is a remote code-execution (RCE) vulnerability that could allow an authenticated user, with limited permissions, to create specially crafted newsletters and email templates that can be used to execute arbitrary code on targeted systems. The vulnerability has a CVSS score of 9.8 and impacts Magento versions 2.1 prior to 2.1.17, Magento 2.2 prior to 2.2.8 and Magento 2.3 prior to 2.3.1.

A second critical bug patched by Magento is an unauthenticated SQL injection vulnerability that could allow an attacker exploiting the flaw to “read from the [Magento] database, [and] extract admin sessions or password hashes and use them to access the backend,” according to Ambionics Security. This would allow site takeover with the stolen credentials.

SOURCE: https://threatpost.com/magento-xss-csrf-...es/143274/
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
Good this has been fixed, especially now that credentials attacks are becoming more popular and sophisticated, which could use flaws to perform malicious activities and access critical information.
[-] The following 1 user says Thank You to Deep900 for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Cloudflare CEO warns AI bots could outnu...
The internet you use...schreckdeividas — 11:03
ScreenToGif 2.43.1
ScreenToGif 2.43.1...harlan4096 — 08:55
uBOLite 2026.322.1735 (already available...
uBOLite 2026.322.1...harlan4096 — 08:54
Microsoft outs Windows 11 KB5085516 to f...
This month, Micros...harlan4096 — 08:53
AV-Test - Awards 2025: celebrating the v...
V-TEST Awards 2025...harlan4096 — 08:50

[-]
Birthdays
Today's Birthdays
avatar (44)battsourIonix
avatar (43)CedricSek
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti
avatar (43)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>