StyleSmuggler zero-day in Magento and Adobe Commerce actively exploited

StyleSmuggler zero-day in Magento and Adobe Commerce actively exploited
View on original source
Category: SciTech
Share
Archive
Like
Online shops based on the open-source e-commerce shop system Magento or the commercial version Adobe Commerce are apparently vulnerable. Attackers can execute malicious code on the servers of the affected online shops without logging in and set up a persistent backdoor. The Dutch e-commerce security firm Sansec discovered the vulnerability and named it StyleSmuggler. The security researchers chose the name because malicious code can be injected via the styles properties. Continue after ad In their blog post of September 5, the Sansec security researchers write that the vulnerability has been actively exploited since September 4, which is why they decided to publish it so early. According to Sansec, all current versions are affected, including Magento 2.4.9, even those with the latest patches from July and August. Patch missing so far So far, no patch is apparently available and Adobe has not yet commented on which versions of Adobe Commerce are affected. As of September 7, the Adobe Security Bulletin was last updated on August 18; the most recent entry concerns a security update from August 11. The next Adobe Patch Day is scheduled for September 8. Adobe has been releasing security updates twice a month since July. It is unclear whether the StyleSmuggler vulnerability will be patched then. So far, there is no advisory and no CVE number. Adobe, as a CNA (CVE Numbering Authority) for its own product, would typically assign this itself. Until a patch is available, Sansec recommends that shop operators who are not Sansec customers and therefore cannot use the in-house security solution Sansec-Shield temporarily disable GraphQL if possible. Furthermore, it is advisable to examine systems for possible remnants. Sansec provides concrete starting points for this, such as searching for PHP files in the media directory. StyleSmuggler triggers the sending of a 'Payment Transaction Failed Email'. An unusually high volume of such emails can also indicate the exploit. Sansec has published a list of so-called Indicators of Compromise (IoC) in the blog post; more details are to follow. The Dutch web hosting provider Disrex also sheds light on StyleSmuggler in a blog post and maintains its own list of IoCs on GitHub. Continue after ad (kst)

(0)Comments

 

A note on cookies

Newshunt uses essential cookies to keep you signed in and to remember your language and country, so the site works the way you expect. With your permission, we'd also like to use analytics cookies to understand how people use Newshunt and improve it over time.

Accepting only affects analytics. To learn more, view our Privacy Policy or Terms & Conditions.