Cross-site request forgery in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8457

 

Cross-site request forgery in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8457

Published: September 15, 2017


Vulnerability identifier: #VU8457
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to perform CSRF attack.

The weakness exists due to improper input validation in the newsletter template. A remote attacker can create a specially crafted HTML page or URL, trick the victim into visiting it, gain access to the system and perform arbitrary actions.


Affected software

Magento Open Source
Adobe Commerce (formerly Magento Commerce)

Remediation

The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.


External References

Related Security Bulletins