Critical vulnerability in Magento puts hundreds of thousands of online stores at risk
A critical remote code execution (RCE) vulnerability has been identified in eBay's popular e-commerce platform, Magento. The vulnerability affects hundreds of thousands of e-commerce seller websites.
Successful exploitation of the vulnerability could allow hackers to compromise any Magento-based e-shop, gaining access to credit card details, as well as other financial and personal customer data
This critical security flaw in Magento stems from a series of vulnerabilities that allow malicious PHP code to be executed on vulnerable web servers. The specific vulnerabilities are located in the core Magento code and affect both main versions of the platform (Magento Community Edition and Magento Enterprise Edition).
[alert variation=”alert-info”]Successful exploitation of the vulnerability and execution of malicious code on a vulnerable server gives attackers the ability to bypass all security mechanisms, gaining full control of the vulnerable online store, as well as its entire database, even leading to the theft of credit card details and other sensitive information.[/alert]
The most worrying thing is that this vulnerability is not new, but it still affects hundreds of thousands of websites. The vulnerability was first discovered in January 2015 by security researchers at Check Point and was immediately reported to the company, which issued a patch to fix it.
However, despite the fact that two and a half months have passed since the patch was released, more than half of Magento-based websites are still vulnerable to attacks, as their administrators have not installed the available patch.
According to research by the company Byte (which has created an online tool that allows e-shop owners to check if their website is vulnerable), more than 140,000 websites are vulnerable to this particular security flaw at the given time.
Therefore, due to the criticality of the vulnerability, Magento website administrators are advised to upgrade immediately, applying the available patch, for the effective protection and security of their online stores, as well as their customer data.
