Singsys blog

Magento Security: Hackers Exploiting Old Plugin Vulnerabilities

Magento Security

FBI has recently released news regarding e-skimming attacks, also known as web skimming. Alongwith with that RiskIQ warned about Magecart attacks. These Magecart attacks are somewhere affecting Magento where hackers are exploiting a three-year-old vulnerability in a Magento plugin to hack online stores and place a malicious script that records and steals buyers’ payment card data. To carry out these e-skimming intrusions, hackers are exploiting the cross-site scripting (XSS) that lies in the Magento Mass Import (MAGMI) plugin. 

(more…)