vendor:
Magento eCommerce Platform Enterprise & Community Edition
by:
K. Gudinavicius, SEC Consult Vulnerability Lab
9
CVSS
CRITICAL
XML eXternal Entity Injection
611
CWE
Product Name: Magento eCommerce Platform Enterprise & Community Edition
Affected Version From: Magento eCommerce Platform Enterprise Edition <= v1.12.0.1, Magento eCommerce Platform Community Edition <= v1.7.0.1
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Local file disclosure via XXE injection
Magento eCommerce platform uses a vulnerable version of Zend framework which is prone to XML eXternal Entity Injection attacks. The SimpleXMLElement class of Zend framework (SimpleXML PHP extension) is used in an insecure way to parse XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. By exploiting this vulnerability an application may be coerced to open arbitrary files and/or TCP connections.
Mitigation:
Upgrade to the latest version of Magento eCommerce Platform Enterprise Edition <= v1.12.0.2 or Magento eCommerce Platform Community Edition <= v1.7.0.2