Magento CoreÖеÄSQL×¢ÈëµÈ¶à¸ö·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-01·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾£º
Magento Commerce2.3,2.2ºÍMagento Open Source2.1
·ì϶¸ÅÊö
MagentoÊÇÒ»Ì×רҵ¿ªÔ´µÄµç×ÓÉÌÎñϵͳ¡£¡£¡£¡£¡£¡£¡£MagentoÉè¼ÆµÃ¼«¶È½Ã½Ý£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÄ£¿£¿£¿£¿£¿é»¯¼Ü¹¹ÏµÍ³ºÍ·á˶µÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£ÆäÃæÏòÆóÒµ¼¶ÀûÓ㬣¬£¬£¬£¬£¬£¬¿É´¦Öø÷·½ÃæµÄÐèÒª£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°½¨ÉèÒ»¸ö¶àÖÖÓô¦ºÍºÏÓÃÃæµÄµç×ÓÉÌÎñÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ô̺¬¹ºÎï¡¢º½ÔË¡¢²úÆ·ÆÀÂ۵ȵȣ¬£¬£¬£¬£¬£¬£¬³ä·ÖÀûÓÿªÔ´µÄ¸öÐÔ£¬£¬£¬£¬£¬£¬£¬Ìṩ´úÂë¿âµÄ¿ª·¢£¬£¬£¬£¬£¬£¬£¬¼«¶È¹æ·¶µÄ³ß¶È£¬£¬£¬£¬£¬£¬£¬Ò×ÓÚÓëµÚÈý·½ÀûÓÃϵͳÎ޷켯³É¡£¡£¡£¡£¡£¡£¡£
Magento°ä²¼ÁËһϵÁиüУ¬£¬£¬£¬£¬£¬£¬Ô̺¬Magento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17 ÒÔ½¨¸´Æäƽ̨ÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¸üнâ¾öµÄÒ»¸ö¹Ø¼ü·ì϶ÊÇSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢´Ó»ùÓÚMagentoµÄÍøÕ¾Ê¹ÓõÄÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÆäËû·ì϶Ô̺¬Ô¶³Ì´úÂëÖ´ÐÓ×¢¿çÕ¾¾ç±¾±àд¡¢È¨ÏÞÌáÉý¡¢¿çÕ¾ÒªÇóαÔìÒÔ¼°ÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£¡£
MagentoÔÚ¹úÄÚµÄÇé¿öÈçÏÂͼ£º
·ì϶ÀûÓãº
SQL×¢Èë·ì϶EXP: https://cxsecurity.com/issue/WLB-2019030247¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
½¨ÒéMagentoÓû§¾¡¿ì¸üе½×îа汾£ºMagento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17£ºhttps://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.sucuri.net/2019/03/sql-injection-in-magento-core.html
https://cxsecurity.com/issue/WLB-2019030247
https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update


¾©¹«Íø°²±¸11010802024551ºÅ