Critical vulnerabilities in the e-commerce platform Magento

Adobe Inc. released update of the open platform for e-commerce organization Magento (2.3.4, 2.3.3-p1 and 2.2.11), which accounts for about 10% the market for online store creation systems (Adobe became the owner of Magento in 2018). This update addresses 6 vulnerabilities, three of which are classified as critical (details have not yet been disclosed):

  • CVE-2020-3716 — the potential for remote code execution via the deserialization of external data;
  • CVE-2020-3718 — bypassing security mechanisms leading to arbitrary code execution on the server side;
  • CVE-2020-3719 — the capability to inject SQL commands, allowing access to data in the database.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster