Vulnerability identifier: #VU8712
Vulnerability risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID:
CWE-352
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Magento Open Source
Web applications /
E-Commerce systems
Adobe Commerce (formerly Magento Commerce)
Web applications /
E-Commerce systems
Vendor:
Adobe
Magento, Inc
Description
The vulnerability allows a remote attacker to perform CSRF attack.
The vulnerability exists due to incorrect validation of the HTTP request origin in Customer Groups functionality when an HTTP POST request is changed to HTTP GET on saving changes to existing groups (/customer/group/save/). The web application ignores "form_key" parameter in HTTP GET request, which allows a remote attacker to create arbitrary customer groups.
Mitigation
Update to version 1.9.3.6, 1.14.3.6, 2.0.16 or 2.1.9.
Vulnerable software versions
Magento Open Source: 1.9.0.0 - 1.9.3.5
Adobe Commerce (formerly Magento Commerce): 1.14.0.0 - 1.14.3.5, 2.0.0 - 2.0.15, 2.1.0 - 2.1.8
External links
https://www.defensecode.com/advisories/DC-2017-09-001_Magento_CSRF_Stored_Cross_Site_Scripting.pdf
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.