Cross-site request forgery in Adobe Commerce (formerly Magento Commerce) - #VU8473

 

Cross-site request forgery in Adobe Commerce (formerly Magento Commerce) - #VU8473

Published: September 15, 2017


Vulnerability identifier: #VU8473
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform CSRF attacks

The vulnerability exists due to anti-CSRF form_key token is not changed after user login. A remote attacker can intercept the token before authorization and perform CSRF attacks  against website users.



Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins