Company
Date Published
Author
DeveloperSteve Coochin
Word count
711
Language
English
Hacker News points
None

Summary

A critical vulnerability was discovered in Magento Ecommerce, Magento Open Source, and Adobe Commerce versions, allowing an unauthenticated user to utilize SQL injection or PHP object injection at the checkout process. A patch was initially released, but further testing revealed it wasn't sufficient to mitigate the issue, leading to a new patch being rolled out to address the vulnerability. The new patch adds a reusable framework function to sanitize user input and provides additional security measures to prevent exploitation of the vulnerability. It is essential to apply both patches and run secure backups before deployment to ensure the security of the platform. Security researchers recommend monitoring public repositories, such as those on GitHub, for potential issues using tools like Snyk, which can alert developers to vulnerabilities and suggest possible fixes.