PT-2015-6239 · Magento · Magento Community Edition+1

Published

2015-04-29

·

Updated

2016-12-06

·

CVE-2015-3458

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Magento Community Edition (CE) version 1.9.1.0 Magento Enterprise Edition (EE) version 1.14.1.0
Description The issue is related to the fetchView function in the Mage Core Block Template Zend class, which does not restrict the stream wrapper used in a template path. This allows remote administrators to include and execute arbitrary PHP files via the phar:// stream wrapper, related to the setScriptPath function. It is unclear whether this issue crosses privilege boundaries, as administrators may already have privileges to include arbitrary files.
Recommendations For Magento Community Edition (CE) version 1.9.1.0, consider restricting access to the fetchView function in the Mage Core Block Template Zend class until a patch is available. For Magento Enterprise Edition (EE) version 1.14.1.0, consider restricting access to the fetchView function in the Mage Core Block Template Zend class until a patch is available. As a temporary workaround, consider disabling the use of the phar:// stream wrapper in template paths to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3458

Affected Products

Magento Community Edition
Magento Enterprise Edition