Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Magento plugs 'dangerous' cross-scripting hole
iTnews ^ | Jan 27 2016 6:51AM (AUS) | Juha Saarinen

Posted on 01/26/2016 7:25:54 PM PST by Utilizer

A new vulnerability in the eBay-owned Magento e-commerce platform could be remotely exploited to take over sites and steal client information, researchers have discovered.

Security vendor Sucuri discovered a stored cross-site scripting (XSS) vulnerability in the core system libraries for Magento Community Edition version 1.9.2.3 and earlier, and the Enterprise Edition version 1.14.2.3 and older.

The critical flaw could be triggered by sending an email to adminstrators.

Sucuri reported the bug to Magento's security team early in November last year. Magento acknowledged the vulnerability on 1 December 2015, but did not issue a patch until 21 January 2016.

The Magento SUPEE-7405 patch bundle fixes the stored XSS flaw, which can also be abused to create admin users and execute commands with full superuser rights.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: ebay; malware; onlinepurchasing; security
A warning for anyone going through ebay. At least a patch has finally been released.
1 posted on 01/26/2016 7:25:54 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Bobalu

I understand you use ebay. You might be interested in this...


2 posted on 01/26/2016 7:33:59 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Thanks for the hedzup my FRiend :-)


3 posted on 01/26/2016 7:36:14 PM PST by Bobalu (I told you so!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

4 posted on 01/26/2016 7:39:09 PM PST by DannyTN
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu

Anytime, mate. Pass the word, right?


5 posted on 01/26/2016 7:41:13 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

hackers can steal information not only from magento store


6 posted on 08/02/2017 7:37:00 AM PDT by OliverTwik
[ Post Reply | Private Reply | To 4 | View Replies]

It’s good to know that the security issue was solved. I recently added one feature, found on https://www.aitoc.com/en/magento.html , to my website. It made my store more reliable and attractive to customers. + I can always rely on magento team support and not ready to switch to shopify or any other platform.


7 posted on 08/02/2017 8:11:25 AM PDT by Muntic0re
[ Post Reply | Private Reply | To 6 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson