Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Overview
A new vulnerability in Magento Open Source and Adobe Commerce, identified by the Dutch security firm Sansec and named StyleSmuggler, is currently being exploited by attackers. This flaw allows malicious code to be executed on online store servers without requiring a login, which poses a significant risk to e-commerce platforms. Sansec reported that attacks began on September 4, 2023, just a day before the advisory was published. Online stores using these platforms are at risk of being backdoored, which can lead to unauthorized access and data breaches. Companies running affected systems need to take this threat seriously and implement necessary security measures to protect their customers and data.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Magento Open Source, Adobe Commerce
- Action Required: Sansec has not specified any patches or updates at this time.
- Timeline: Disclosed on September 5, 2023
Original Article Summary
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
Impact
Magento Open Source, Adobe Commerce
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on September 5, 2023
Remediation
Sansec has not specified any patches or updates at this time. Users should consider implementing security measures such as firewalls, intrusion detection systems, and regular monitoring of their servers for unusual activity to mitigate risks associated with this vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Zero-day, Vulnerability, Adobe.