Magento's e-commerce platform has fixed 75 vulnerabilities.

In the open platform for organizing e-commerce Magento, which occupies about 20% the market of systems for creating online stores, three vulnerabilities have been identified vulnerabilities, the combination of which allows an attack to execute its code on the server, gain full control over the online store, and organize payment redirection. Vulnerabilities four vulnerabilities have been fixed in releases Magento 2.3.2, 2.2.9, and 2.1.18, in which a total of 75 security-related issues were resolved.

One of the issues allows an unauthenticated user to place JavaScript code (XSS) that can be executed when viewing the abandoned orders log in the admin interface. The essence of the vulnerability lies in the ability to bypass text cleaning through the escapeHtmlWithLinks() function when processing notes in the cancellation form on the checkout start screen (using the tag "a href=http://onmouseover=…" nested inside another tag). This issue occurs when using the built-in Authorize.Net module, which processes credit card payments.

To gain complete control using JavaScript code in the context of the current store staff session, a second vulnerability is exploited, allowing the upload of a phar file disguised as an image (conducting attacks "Phar deserialization"). The phar file can be uploaded through the image insertion form in the built-in WYSIWYG editor. Once the attacker executes their PHP code, they can then alter payment details or intercept customer credit card information.

Interestingly, details about the XSS issue were sent to Magento developers back in September 2018, after which a patch was released at the end of November, which turned out to only resolve one specific case and could be easily bypassed. In January, it was additionally reported that it was possible to upload a phar file disguised as an image, and it was demonstrated how the combination of the two vulnerabilities could be used to compromise online stores. By the end of March, issues with phar files were fixed in Magento 2.3.1,
2.2.8, and 2.1.17, but the XSS fix was forgotten even though the ticket for the issue was closed. In April, the analysis of XSS resumed, and the issue was resolved in releases 2.3.2, 2.2.9, and 2.1.18.

It should be noted that in the specified releases, 75 vulnerabilities have also been addressed, of which the severity level is marked as critical for 16, and 20 issues could lead to the execution of PHP code or SQL injection. Most critical issues can only be exploited by an authenticated user, but as shown above, performing authenticated operations is not difficult to achieve through XSS vulnerabilities, of which several dozen have been addressed in the highlighted releases.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster