{"id":"GHSA-prpf-cj87-hwvr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-prpf-cj87-hwvr","summary":"Magento Patch SUPEE-10752 - Multiple security enhancements vulnerabilities","details":"Magento Commerce 1.14.3.9 and Open Source 1.9.3.9 bring essential security enhancements with Patch SUPEE-10752. These updates address various vulnerabilities, including authenticated Admin user remote code execution (RCE), cross-site request forgery (CSRF), and more.\n\nKey Security Improvements:\n\n- APPSEC-2001: Authenticated Remote Code Execution (RCE) using custom layout XML\n- APPSEC-2015: Authenticated Remote Code Execution (RCE) through the Create New Order feature (Commerce only)\n- APPSEC-2042: PHP Object Injection and RCE in the Magento admin panel (Commerce Target Rule module)\n- APPSEC-2029: PHP Object Injection and Remote Code Execution (RCE) in the Admin panel (Commerce)\n- APPSEC-2007: Authenticated SQL Injection when saving a category\n- APPSEC-2027: CSRF is possible against Web sites, Stores, and Store Views\n- APPSEC-1882: The cron.php file can leak database credentials\n- APPSEC-2006: Stored cross-site scripting (XSS) through the Enterprise Logging extension\n- APPSEC-2005: Persistent Cross-Site Scripting (XSS) injection in Configuration table\n- APPSEC-1880: Cross-Site Scripting (XSS) through the Admin Username in the CMS Revision Editor (Commerce only)\n- APPSEC-2004: Cross-Site Scripting (XSS) through Remote File Inclusion\n- APPSEC-1988: Path traversal vulnerability in templates\n- APPSEC-1987: Reflective cross-site scripting (XSS) through filter manipulation\n- APPSEC-2034: XSS in Admin Create Order Configure Product Via Compatible File Extensions\n- APPSEC-1876: Cross-site scripting (XSS) in Admin Bundle Product Bundle Items Tab through Product SKU\n- APPSEC-1874: Cross-Site Scripting (XSS) in the Admin Gift Registry Type Edit via Attribute Group\n- APPSEC-1872: Cross-Site Scripting (XSS) in the Admin Manage Catalog Events list through category name\n- APPSEC-1928: Stored XSS in Downloadable Product Links title - frontend\n- APPSEC-1871: Cross-Site Scripting (XSS) in the Admin Manage Customer Rewards points history using the Reason field\n- APPSEC-1870: Cross-Site Scripting (XSS) in Admin Manage Invitations list through Invitee email address\n- APPSEC-1972/APPSEC-2103: Admin password change does not force the logout of the Admin user\n- APPSEC-1934: Systemic Cross-Site Request Forgery (CSRF) on the Checkout page\n- APPSEC-1917: Password theft though uploaded video and Auth Prompt password theft vulnerability\n- APPSEC-1993: IP spoofing\n\nPatches and upgrades are available for the following Magento versions:\n\n- Magento Commerce 1.9.0.0-1.14.3.9: SUPEE-10752 or upgrade to Magento Commerce 1.14.3.9.\n- Magento Open Source 1.5.0.0-1.9.3.9: SUPEE-10752 or upgrade to Magento Open Source 1.9.3.9.\n\n\n\n","published":"2024-05-15T22:32:47Z","modified":"2024-11-29T05:26:11.130931Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"magento/community-edition","fixedVersion":"1.9.3.9"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/magento1ce/2018-06-29.yaml"},{"type":"PACKAGE","url":"https://github.com/magento/magento2"},{"type":"WEB","url":"https://magento.com/security/patches/supee-10752"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:26:11.130931Z"}}