Cross-site request forgery in Adobe Commerce (formerly Magento Commerce) - #VU8471

 

Cross-site request forgery in Adobe Commerce (formerly Magento Commerce) - #VU8471

Published: September 15, 2017


Vulnerability identifier: #VU8471
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform CSRF attacks

The vulnerability exists due to absence of CSRF protection in customer registration process. A remote attacker can perform CSRF attacks and create arbitrary number of user accounts on the website.



Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins