HomeSecurityXSS Bug in Magento, online stores at risk!

XSS Bug in Magento, online stores at risk!

Magento has released patches to fix a critical security flaw in the CMS that has affected a large portion of online stores across the Internet.

XSS Bug in Magento, online stores at risk!

The bug is a stored XSS (cross-site scripting) vulnerability that can be exploited when registering a new user account or when users change their email address on their current account.

The problem lies in the way the CMS filters data entered into the email field for customers. As cybersecurity tools vendor Sucuri, the email is not being adequately filtered for “bad” characters.

This improper data filtering mechanism allows attackers to insert malicious code along with their email address.

If an attacker then places an order from an account to an account with an infected email address, when the site administrator opens the order in the backend, the malicious code will also be executed.

xss-bug-in-magento-allows-attackers-to-take-over-online-shops-499331-3

JavaScript code can be used to access cookies, so that the attacker can steal the administrator's cookie and use it to gain unauthorized access to the site later. Other actions can also be performed, and the capabilities of the attack depend on the skills of the attacker.

On its own vulnerability severity scale, Sucuri has rated the bug a 7 out of 10.

In theory, the bug is similar to another XSS bug discovered in the WordPress plugin, Jetpack, by Sucuri in October. This bug again allowed attackers to execute malicious code inside the WordPress backend via malicious code that was associated with email addresses submitted through a comment form.

The affected Magento include Magento Community Edition 1.9.2.2 and below, and Magento Enterprise Edition 1.14.2.2 and below. The recent 2.x version is not affected by this issue, but there is another stored XSS bug that also affects 2.x.

For users running an older version of Magento, store administrators should update their online stores as soon as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS