Magento CoreÖеÄSQL×¢ÈëµÈ¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-01

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾£º


Magento Commerce2.3,2.2ºÍMagento Open Source2.1


·ì϶¸ÅÊö


MagentoÊÇÒ»Ì×רҵ¿ªÔ´µÄµç×ÓÉÌÎñϵͳ¡£MagentoÉè¼ÆµÃ¼«¶È½Ã½Ý £¬ÓµÓÐÄ£¿é»¯¼Ü¹¹ÏµÍ³ºÍ·á˶µÄÖ°ÄÜ¡£ÆäÃæÏòÆóÒµ¼¶ÀûÓà £¬¿É´¦Öø÷·½ÃæµÄÐèÒª £¬ÒÔ¼°½¨ÉèÒ»¸ö¶àÖÖÓô¦ºÍºÏÓÃÃæµÄµç×ÓÉÌÎñÍøÕ¾¡£Ô̺¬¹ºÎï¡¢º½ÔË¡¢²úÆ·ÆÀÂ۵ȵÈ £¬³ä·ÖÀûÓÿªÔ´µÄ¸öÐÔ £¬Ìṩ´úÂë¿âµÄ¿ª·¢ £¬¼«¶È¹æ·¶µÄ³ß¶È £¬Ò×ÓÚÓëµÚÈý·½ÀûÓÃϵͳÎ޷켯³É¡£


Magento°ä²¼ÁËһϵÁиüР£¬Ô̺¬Magento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17 ÒÔ½¨¸´Æäƽ̨ÖеĶà¸ö°²È«·ì϶¡£¸üнâ¾öµÄÒ»¸ö¹Ø¼ü·ì϶ÊÇSQL×¢Èë·ì϶ £¬¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐжñÒâ´úÂë £¬²¢´Ó»ùÓÚMagentoµÄÍøÕ¾Ê¹ÓõÄÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢¡£ÆäËû·ì϶Ô̺¬Ô¶³Ì´úÂëÖ´ÐÓ×¢¿çÕ¾¾ç±¾±àд¡¢È¨ÏÞÌáÉý¡¢¿çÕ¾ÒªÇóαÔìÒÔ¼°ÐÅϢй¶·ì϶¡£
MagentoÔÚ¹úÄÚµÄÇé¿öÈçÏÂͼ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


·ì϶ÀûÓãº


SQL×¢Èë·ì϶EXP: https://cxsecurity.com/issue/WLB-2019030247¡£


½¨¸´½¨Òé


½¨ÒéMagentoÓû§¾¡¿ì¸üе½×îа汾£ºMagento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17£ºhttps://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update¡£


²Î¿¼Á´½Ó


https://blog.sucuri.net/2019/03/sql-injection-in-magento-core.html
https://cxsecurity.com/issue/WLB-2019030247
https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update