Server-side request forgery in Magento Open Source - #VU18099

 

Server-side request forgery in Magento Open Source - #VU18099

Published: March 30, 2019


Vulnerability identifier: #VU18099
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to incorrect handling of API calls. A remote authenticated user with privileges to configure store settings can execute arbitrary PHP code on the system.



Affected software

Magento Open Source

Remediation

Install updates from vendor's website.

Magento Open Source - addressed in versions 2.1.17, 2.2.8, 2.3.1

External References

Related Security Bulletins