Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Exploit Discovered in Magento Ecommerce Platform Endangers Online Transactions
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Exploit Discovered in Magento Ecommerce Platform Endangers Online Transactions

Highlights

  • Magento's vulnerability allows backdoor insertion.

  • Attackers use XML code to steal customer data.

  • Immediate action and updates are crucial for security.

Kaan Demirel
Last updated: 5 April, 2024 - 3:30 pm 3:30 pm
Kaan Demirel 1 year ago
Share
SHARE

A critical security weakness has been identified in the Magento ecommerce platform, potentially exposing numerous online stores and their customers to cybersecurity risks. The flaw, assigned CVE-2024-20720, enables cybercriminals to establish persistent backdoors on Magento servers, thereby threatening the integrity of a multitude of ecommerce sites. This exploitation occurs through a sophisticated manipulation of Magento’s layout template system, allowing the insertion of malicious XML code into the layout_update database table. This code is subsequently executed whenever a customer navigates to the checkout cart, making use of Magento’s layout parser alongside the beberlei/assert package to run a specific command, ‘sed’, which installs a backdoor into the CMS controller.

Contents
Widespread Impact and Attack StrategiesExperts Recommend Swift ActionComparative Insights from Related ReportsUseful Information for the Reader

Widespread Impact and Attack Strategies

The assault on Magento’s security not only grants hackers sustained access to the systems but also paves the way for the addition of further malicious payloads. For instance, a counterfeit Stripe payment skimmer has been detected that siphons off payment details from customers. This stolen data is then transmitted to a compromised Magento store, amplifying the attackers’ ability to acquire sensitive information. A collective of IP addresses linked to the culprits suggests a well-coordinated effort to exploit this vulnerability across an array of ecommerce sites.

The vulnerability revelation coincides with a marked increase in digital skimming activities, also referred to as Magecart attacks. These attacks, which have been escalating since 2015, specifically target online shopping platforms to hijack credit card information during checkout. To counteract this vulnerability, Sansec has recommended urgent actions for merchants using Magento. They advise running the eComscan scanner to detect any hidden backdoors and suggest updating Magento to the latest patched versions to secure their platforms against impending threats.

Experts Recommend Swift Action

Addressing the vulnerability, security experts urge Magento store owners to take immediate steps to secure their systems. The recommended course of action includes employing the eComscan scanner tool to locate concealed backdoors and upgrading to more secure versions of Magento. These versions include 2.4.6-p4, 2.4.5-p6, or 2.4.4-p7, all of which contain patches for this particular security gap. This incident underscores the continuous risk online merchants face and the necessity for stringent, updated security protocols to protect against these evolving cyber threats.

Comparative Insights from Related Reports

Exploring similar incidents, a report from Security Magazine titled “Rise in Ecommerce Platform Breaches” indicates a growing trend in security breaches among various ecommerce platforms, suggesting a broader issue beyond Magento. Another related article from Infosecurity Magazine, “New Payment Skimmers Target Ecommerce Sites,” delves into the details of how cybercriminals are developing new skimming techniques to exploit online payment systems, further confirming the need for amplified vigilance and robust security measures within the ecommerce sector.

Useful Information for the Reader

– Always update to the latest security-patched versions of ecommerce platforms.
– Employ dedicated scanning tools like eComscan to uncover hidden threats.
– Stay informed about the latest cyber threats and skimming techniques targeting online stores.

The discovery of such vulnerabilities highlights the constant battle between cybercriminals and the security defenses of online platforms. This incident serves as a critical warning to the ecommerce industry to stay alert and proactive in implementing security measures. As the tactics of attackers evolve, so must the strategies to defend against them, ensuring the safety of both the merchants’ interests and their customers’ private information. The ecommerce community must continue to prioritize security, not just as a response to threats, but as an integral part of their operational framework.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

US Authorities Dismantle Botnets and Indict Foreign Nationals

SonicWall Customers Face Spike in Device Vulnerabilities

Cyberattack Forces PowerSchool to Face Extortion Scandal

CrowdStrike Faces Workforce Reduction Amid Financial Shifts

Authorities Seize DDoS Platforms in Multi-National Operation

Share This Article
Facebook Twitter Copy Link Print
Kaan Demirel
By Kaan Demirel
Kaan Demirel is a 28-year-old gaming enthusiast residing in Ankara. After graduating from the Statistics department of METU, he completed his master's degree in computer science. Kaan has a particular interest in strategy and simulation games and spends his free time playing competitive games and continuously learning new things about technology and game development. He is also interested in electric vehicles and cyber security. He works as a content editor at NewsLinker, where he leverages his passion for technology and gaming.
Previous Article Why Xbox Field Trips for Education?
Next Article Chinese Espionage Groups Attack Ivanti VPNs with Advanced Tactics

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

North American Robot Orders Stabilize in Early 2025
Robotics
UR15 Boosts Automation Speed in Key Industries
Robotics
NHTSA Questions Tesla’s Robotaxi Plans in Austin
Electric Vehicle
Tesla’s Secretive Test Car Activities Ignite Curiosity
Electric Vehicle
AI Reshapes Global Workforce Dynamics
AI Technology
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?