Adobe patches critcal bug in e-commerce software
The flaw, which allowed attackers to run their own code on websites, was being exploited in wild
Adobe has fixed a critical vulnerability in its e-commerce software that allowed attackers to run their own code on merchants' sites.
The bug, which was being exploited in the wild, affects Adobe Commerce and Magento Commerce, software that allow merchants to host and manage online stores. It is rated critical, with a 9.8 score under the Common Vulnerability Scoring System (CVSS), and is described as improper input validation bug that allows attackers to execute arbitrary code by manipulating input fields.
"Adobe is aware that CVE-2022-24086 has been exploited in the wild in very limited attacks targeting Adobe Commerce merchants," the company warned in an advisory.
The vulnerability affects v2.4.3 and earlier of the Adobe products, and the company has released a patch. With little other information about the bug, there are no clear workarounds for the vulnerability other than to patch systems immediately.
Security bugs like these allow attackers to inject their own code onto e-commerce sites, which could skim a customer's credit card details and login credentials. One of the most popular skimming groups is Magecart, originally a single group that experts have seen morph into multiple groups.
Adobe acquired Magento in 2018 and rebranded its Magento Commerce product as Adobe Commerce. The company still offers a free version called Magento Open Source for building ecommerce stores.
Adobe Commerce offers a page builder for product stores, personalized product recommendations, and real-time inventory management that allows vendors to arrange for home delivery or pickup at the store. It also offers reporting capabilities to help visualize store performance.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
Putting the insurance industry back in safe hands
The role of payments in digital transformation
In September, Adobe added a new Payment Services tool to the Commerce product that allows merchants to support more payment services, such as Venmo and PayPal.
Security company Malwarebytes recently noted an increase in Magecart activity after one of the groups began targeting large numbers of ecommerce scores. Much of this activity focuses on Magento 1, which has not been supported since 2020. These attackers used a vulnerability in the Quickview plugin to create rogue Magento admin users that could run code with elevated privileges.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Morgan Stanley research warns AI is having a huge impact on jobsNews Analysis of five sectors highlights an "early warning sign" of AI’s impact on jobs
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches
-
Security experts claim the CVE Program isn’t up to scratch anymore — inaccurate scores and lengthy delays mean the system needs updatedNews CVE data is vital in combating emerging threats, yet inaccurate ratings and lengthy wait times are placing enterprises at risk
-
IBM AIX users urged to patch immediately as researchers sound alarm on critical flawsNews Network administrators should patch the four IBM AIX flaws as soon as possible
-
Critical Dell Storage Manager flaws could let hackers access sensitive data – patch nowNews A trio of flaws in Dell Storage Manager has prompted a customer alert
-
Flaw in Lenovo’s customer service AI chatbot could let hackers run malicious code, breach networksNews Hackers abusing the Lenovo flaw could inject malicious code with just a single prompt
