Interestana
Home/News/Unpatched Magento Zero-Day Exploited to Backdoor Stores
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Unpatched Magento Zero-Day Exploited to Backdoor Stores

Unpatched Magento Zero-Day Exploited to Backdoor Stores

An unpatched zero-day vulnerability affecting Magento Open Source and Adobe Commerce is being actively exploited by attackers to gain unauthorized access and install backdoors on online stores. Dutch e-commerce security firm Sansec disclosed the flaw on September 5, reporting that malicious activity began as early as September 4. The vulnerability, which Sansec has named StyleSmuggler, allows attackers to execute malicious code on a store's server without requiring any login credentials. This means that even stores with strong password policies and multi-factor authentication are susceptible if they have not yet applied a patch for this specific issue.

Sansec's advisory detailed that the exploitation involves injecting malicious PHP code into the system. This code can then be used to create administrative accounts, steal sensitive customer data, or redirect traffic to fraudulent websites. The security firm emphasized that the vulnerability is particularly dangerous because it bypasses standard security measures, enabling attackers to establish a persistent presence within the compromised e-commerce environment. The lack of an immediate patch from Adobe, the vendor for Adobe Commerce and the steward of Magento Open Source, leaves a significant window of opportunity for malicious actors.

Magento Open Source is a widely used, free, and open-source e-commerce platform, while Adobe Commerce is its commercial counterpart offering enhanced features and support. Both platforms share a common codebase, meaning the StyleSmuggler vulnerability affects a broad spectrum of online retailers. Sansec's discovery and early warning aim to alert affected businesses and encourage prompt mitigation efforts. The firm has not yet released specific technical details of the exploit to prevent further widespread abuse, but it is working with Adobe to develop and distribute a fix. Retailers using either Magento Open Source or Adobe Commerce are strongly advised to monitor for official security bulletins from Adobe and prepare to apply any released patches as soon as possible.

The exploitation of this zero-day vulnerability highlights the ongoing challenges in securing complex e-commerce platforms. Attackers continuously seek out novel ways to compromise systems, often targeting unpatched or newly discovered flaws. The StyleSmuggler vulnerability's ability to grant administrative access without authentication makes it a high-priority threat for online businesses that handle customer data and financial transactions. Sansec's proactive disclosure, while potentially increasing awareness among attackers, also serves as a critical alert for the e-commerce community to bolster their defenses against this specific threat. The firm's ongoing investigation and collaboration with Adobe are crucial steps in addressing this security incident and preventing further damage to online retailers.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next