Ecommerce sites across the world could be at risk from this dangerous security flaw, so patch now
Adobe Commerce and Magento platforms thought to be affected
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
A catastrophic vulnerability was recently discovered inAdobeCommerce and Magento, but some of thebest ecommerce platformsoperating these tools seem largely uninterested in applying a patch.
As a result, “millions” of sites are open to attacks that could have devastating consequences, experts have warned.
As reported byBleepingComputer, cybersecurity researchers from Sansec discovered an improper restriction of XML external entity reference (‘XXE’) vulnerability, and dubbed it “CosmicSting”. It is now being tracked as CVE-2024-34102, and carries a severity score of 9.8 (critical).
Patch and mitigations
“CosmicSting (aka CVE-2024-34102) is the worst bug to hit Magento and Adobe Commerce stores in two years,” Sansec said in a security advisory. “In itself, it allows anyone to read private files (such as those withpasswords). However, combined with the recent iconv bug in Linux, it turns into the security nightmare of remote code execution.”
Here are the product versions affected by CosmicSting:
If your business is running any of the above, make sure to apply the patch - which was already made available - as soon as possible.
Sansec says that despite the vulnerability being made public more than a week ago, some 75% of Adobe Commerce and Magento users are yet to patch up. There is currently no evidence of in-the-wild abuse, and Adobe did not publish technical details so at to not give hackers any hints. However, Sansec says that the patch can be reverse-engineered and used to learn more about the bug.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Those who are unable to apply the patch immediately are advised to apply the mitigations found onthis link.
More from TechRadar Pro
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
This new phishing strategy utilizes GitHub comments to distribute malware
Should your VPN always be on?
GoPro Max 2 hit by further delays – 2025 is the earliest we’ll see the 360-degree action cam