Quantcast
Channel: Exploit Collector
Viewing all articles
Browse latest Browse all 13315

Magento Cross Site Requst Forgery / Cross Site Scripting

$
0
0

During a security audit of Magento Community Edition / Open Source and Commerce, cross site request forgery and stored cross site scripting vulnerabilities were discovered that could lead to administrator account takeover, putting the website customers and their payment information at risk. Versions affected include Magento CE 1 prior to 1.9.3.6, Magento Commerce prior to 1.14.3.6, Magento 2.0 prior to 2.0.16, and Magento 2.1 prior to 2.1.9.


MD5 | b8e9abcbfbba8f6e6349871a393da400



Viewing all articles
Browse latest Browse all 13315

Trending Articles