Blog | G5 Cyber Security

Security Advisory: Stored XSS in Magento

A Stored XSS vulnerability affecting Magento platform can be easily exploited remotely. The vulnerability affects almost every install of Magento CE <1.9.9,2.3, Magento EE: 1.14.3 and Magent EE <114.2.1.3. The bug is located inside Magento core libraries, more specifically within the administrators backend. Unless you're behind a WAF or you have a very heavily modified administration panel, youre at risk, this issue could be used by attackers to take over your site."] Source: https://blog.sucuri.net/2016/01/security-advisory-stored-xss-in-magento.html

Exit mobile version