CVE-2018-5301: CSRF
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
composer/magento/community-editionto a version that resolves this vulnerability.Fixed in 2.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5301?
CVE-2018-5301 is classified as a medium severity vulnerability due to the potential for customer address deletion.
How do I fix CVE-2018-5301?
To mitigate CVE-2018-5301, upgrade to Magento Community Edition 2.0.10 or 2.1.2 or later.
What versions of Magento are affected by CVE-2018-5301?
CVE-2018-5301 affects Magento Community Edition and Enterprise Edition versions prior to 2.0.10 and 2.1.2.
What type of vulnerability is CVE-2018-5301?
CVE-2018-5301 is a Cross-Site Request Forgery (CSRF) vulnerability.
What impact does CVE-2018-5301 have on users?
CVE-2018-5301 allows an attacker to delete a customer's address from the address book without their consent.