Close the Magento security vulnerability now!

Close the Magento security vulnerability now!

Source: Critical Security Advisory: Remote Code Execution (RCE) Vulnerability | Magento

Given its importance, I want to point out once again here that the security vulnerability needs to be fixed (patch SUPEE-5344).

Most of us should already have applied the patch in February. Remote execution vulnerabilities must always be patched immediately, since they make virtually every imaginable malicious action possible.

Anyone who has not yet patched their own shop or the shops they maintain should do so immediately, and ideally inspect the system straight away for possible compromises, since the shop has effectively been available online without protection for several months.

Magento has set up a special page where you can test your own shop.

http://magento.com/security-patch

More technical information about the vulnerability can be found from its discoverers at Checkpoint.

http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability/