The developers of the popular EBay platform, Magento, promptly patched critical vulnerabilities
Security researchers have discovered two vulnerabilities in the popular e-commerce platform eBay, specifically an XML eXternal Entity (XXE) injection vulnerability and a remote code execution (RCE) vulnerability.
The vulnerabilities were discovered by researchers Dawid Golunski and Ebrahim Hegazy respectively.
Both vulnerabilities were responsibly reported to eBay, and the company was quick to patch them, releasing an urgent security update for the platform.
The first vulnerability (XXE) was found in PHP's FastCGI Process Manager and was rated by eBay developers as highly critical, with a CVSS score of 7.5 out of 10. As researcher Dawid Golunski points out, the security flaw affects Zend-Framework, the PHP toolkit on which Magento Community and Enterprise Editions are built.
“Through the use of multibyte encodings in XML, it is possible to bypass satinization and carry out XXE attacks,” errors that can lead to DoS (Denial-of-Service) attacks against Magento-based eshops or even remote code execution on the platform,” the researcher says.
The second vulnerability identified, based on the findings of researcher Ebrahim Hegazy, “can be exploited to exploit certain unsanitized form fields in the installation package, to execute unauthorized PHP code from the installer.”
However, successful exploitation of this vulnerability requires the presence of the installation folder on the vulnerable online store's server, making it exploitable only in cases where basic security practices have not been followed. Therefore, the vulnerability, according to MageReport.com, affects only a small number of Magento installations worldwide.

