#VU18722 Server-Side Request Forgery (SSRF) in Magento Open Source
Published: June 10, 2019
Magento Open Source
Adobe
Description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to the unsafe handling of an API call to a core bundled extension. A remote authenticated attacker with privileges to configure store settings can execute arbitrary code execution through server-side request forgery.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.