Miggo Logo

GHSA-cv25-3pxr-4q7x:
Magento Open Source Security Advisory: Patch SUPEE-10975

N/A

CVSS Score

Basic Information

CVE ID
-
EPSS Score
-
CWE
-
Published
5/15/2024
Updated
5/15/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
magento/community-editioncomposer>= 1.9.0.0, < 1.14.4.01.14.4.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

Key vulnerabilities were identified through pattern matching against Magento's architecture and common exploit vectors:

  1. RCE vulnerabilities consistently involved unsafe unserialization patterns in dataflow/customer import modules
  2. XSS issues mapped to admin controllers rendering user-controlled data without escaping
  3. CSRF gaps matched controller actions missing form key validation
  4. Confidence levels reflect alignment with Magento's code structure and vulnerability descriptions, though lack of direct code access introduces medium uncertainty for some entries

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

M***nto *omm*r** *.**.*.* *n* Op*n Sour** *.*.*.* **v* ***n *n**n*** wit* *riti**l s**urity up**t*s to ***r*ss multipl* vuln*r**iliti*s, in*lu*in* r*mot* *o** *x**ution (R**), *ross-sit* s*riptin* (XSS), *ross-sit* r*qu*st *or**ry (*SR*), *n* mor*. T

Reasoning

K*y vuln*r**iliti*s w*r* i**nti*i** t*rou** p*tt*rn m*t**in* ***inst M***nto's *r**it**tur* *n* *ommon *xploit v**tors: *. R** vuln*r**iliti*s *onsist*ntly involv** uns*** uns*ri*liz*tion p*tt*rns in **t**low/*ustom*r import mo*ul*s *. XSS issu*s m*p