Scworld
Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A newly disclosed vulnerability named 'PolyShell' affects all stable versions of Magento Open Source and Adobe Commerce, allowing unauthenticated remote code execution (RCE) and account takeover. The flaw arises from the handling of file uploads in Magento's REST API, specifically when a product option is set to type 'file'. Attackers can upload a polyglot file that functions as both an image and a script, potentially leading to severe security breaches. Although Adobe has released a fix in an alpha version of 2.4.9, production versions remain vulnerable. eCommerce security firm Sansec warns that exploit methods are already circulating, and automated attacks are anticipated soon. Store administrators are advised to restrict access to the upload directory and verify web server configurations until a patch for production versions is available.
Key Points: • The 'PolyShell' vulnerability allows unauthenticated RCE and account takeover on Magento systems. • Adobe has released a fix in an alpha version, but production versions are still vulnerable. • Sansec warns of circulating exploit methods and expects automated attacks to commence soon.