CISOOnline

Adobe Commerce max-severity bug comes under active attack

Adobe has released an emergency hotfix, VULN-393411, for the vulnerability. But because attackers had three days to exploit the flaw before a fix arrived, Sansec warns that patching alone isn’t enough for stores that may already have been compromised.

Attack triggered through failed payment email

StyleSmuggler’s first trick is to get malicious PHP code into data that Magento itself will write out, such as a payment failure report. “StyleSmuggler deliberately triggers Magento’s standard ‘Payment Transaction Failed Reminder’email,” the researchers explained. “Unexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification.”

The attackers abuse Magento’s template processing by passing specially crafted “styles properties,” allowing the poisoned data, the injected PHP code, to execute on the server.



Source link