Magento CoreÖеÄSQL×¢ÈëµÈ¶à¸öÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-01Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾£º
Magento Commerce2.3,2.2ºÍMagento Open Source2.1
Îó²î¸ÅÊö
MagentoÊÇÒ»Ì×רҵ¿ªÔ´µÄµç×ÓÉÌÎñϵͳ¡£¡£¡£¡£¡£MagentoÉè¼ÆµÃºÜÊÇÎÞа£¬£¬£¬£¬£¬£¬£¬£¬¾ßÓÐÄ£¿£¿£¿£¿é»¯¼Ü¹¹ÏµÍ³ºÍ¸»ºñµÄ¹¦Ð§¡£¡£¡£¡£¡£ÆäÃæÏòÆóÒµ¼¶Ó¦Ó㬣¬£¬£¬£¬£¬£¬£¬¿É´¦Öóͷ£¸÷·½ÃæµÄÐèÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔ¼°½¨ÉèÒ»¸ö¶àÖÖÓÃ;ºÍÊÊÓÃÃæµÄµç×ÓÉÌÎñÍøÕ¾¡£¡£¡£¡£¡£°üÀ¨¹ºÎï¡¢º½ÔË¡¢²úƷ̸Â۵ȵȣ¬£¬£¬£¬£¬£¬£¬£¬³ä·ÖʹÓÿªÔ´µÄÌØÕ÷£¬£¬£¬£¬£¬£¬£¬£¬Ìṩ´úÂë¿âµÄ¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬·ÇͨÀý·¶µÄ±ê×¼£¬£¬£¬£¬£¬£¬£¬£¬Ò×ÓÚÓëµÚÈý·½Ó¦ÓÃϵͳÎ޷켯³É¡£¡£¡£¡£¡£
MagentoÐû²¼ÁËһϵÁиüУ¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Magento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17 ÒÔÐÞ¸´Æäƽ̨ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¸üнâ¾öµÄÒ»¸öÒªº¦Îó²îÊÇSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬²¢´Ó»ùÓÚMagentoµÄÍøÕ¾Ê¹ÓõÄÊý¾Ý¿âÖлñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ÆäËûÎó²î°üÀ¨Ô¶³Ì´úÂëÖ´ÐС¢¿çÕ¾¾ç±¾±àд¡¢È¨ÏÞÌáÉý¡¢¿çÕ¾ÇëÇóαÔìÒÔ¼°ÐÅϢй¶Îó²î¡£¡£¡£¡£¡£
MagentoÔÚº£ÄÚµÄÇéÐÎÈçÏÂͼ£º
Îó²îʹÓãº
SQL×¢ÈëÎó²îEXP: https://cxsecurity.com/issue/WLB-2019030247¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
½¨ÒéMagentoÓû§¾¡¿ì¸üе½×îа汾£ºMagento Commerce2.3.1,2.2.8ºÍMagento Open Source2.1.17£ºhttps://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.sucuri.net/2019/03/sql-injection-in-magento-core.html
https://cxsecurity.com/issue/WLB-2019030247
https://magento.com/security/patches/magento-2.3.1-2.2.8-and-2.1.17-security-update


¾©¹«Íø°²±¸11010802024551ºÅ