Sansec logo

Magento 2 XSS Admin hijack vulnerability

Sansec

by Sansec Support

Published in Knowledgebase

On July 2nd, 2019, several vulnerabilities were published by RIPSTECH. They can be exploited by placing a specially crafted order. Once your staff views the order in the backend, their session is leaked to the attacker. Subsequently, the attacker uses another vulnerability to gain direct access to the server.

It was fixed in the following Magento versions:

Magento 2.1.18 Magento 2.2.9 Magento 2.3.2

If you are running a Magento 2 store with an older version, we recommend to urgently update to the latest version. See the release statement from Magento for more information.

Need expert advice? We are here to help!

Stay up to date with the latest eCommerce attacks

Sansec logo

experts in eCommerce security

TwitterLinkedinEmail

Terms & Conditions
|
Privacy & Cookie Policy
Company Reg 77165187
|
Tax NL860920306B01