Cross-site request forgery in Magento Open Source and Adobe Commerce (formerly Magento Commerce) - #VU8457
Published: September 15, 2017
Vulnerability identifier: #VU8457
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to perform CSRF attack.
The weakness exists due to improper input validation in the newsletter template. A remote attacker can create a specially crafted HTML page or URL, trick the victim into visiting it, gain access to the system and perform arbitrary actions.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce (formerly Magento Commerce)
Remediation
The vulnerability is addressed in the following versions:
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.
Magento Open Source 1.9.3.6, Magento Commerce 1.14.3.6, Magento 2.0.16 and 2.1.9.