Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Newly Discovered Vulnerability Poses Risk to Millions of Online Stores
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Newly Discovered Vulnerability Poses Risk to Millions of Online Stores
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Vulnerabilities » Newly Discovered Vulnerability Poses Risk to Millions of Online Stores

Vulnerabilities

Newly Discovered Vulnerability Poses Risk to Millions of Online Stores

A critical security vulnerability has been identified on e-commerce sites that are developed using the Adobe Commerce and Magento. This vulnerability has the potential to escalate to remote code execution, enabling attackers to access sensitive files.

Marco Rizal
Last updated: August 21, 2024 10:20 am
By Marco Rizal - Editor, Journalist 2 Min Read
Share
E Commerce Stores Vulnerability
SHARE

The online e-commerce industry is currently facing a significant concern due to the recent discovery of a security vulnerability called “CosmicSting” (CVE-2024-34102), which is particularly affecting the Magento and Adobe Commerce platforms.

This critical vulnerability has the potential to pose a significant security risk, potentially compromising the data of millions of online stores on a global scale.

CosmicSting exploits a critical vulnerability that enables attackers to obtain illicit access to sensitive files, including those that contain critical passwords.

When coupled with a recent Linux flaw (CVE-2024-2961), the vulnerability can escalate to remote code execution, allowing hackers to exert complete control over compromised websites.

With that, the registration credentials of users who created an account on a compromised online store may be at risk of being stolen.

Additionally, a substantial online store with hundreds of thousands of account registrations can pose a significant privacy and security risk.

The vulnerability was first discovered by Sansec, a prominent e-commerce security firm, which has identified CosmicSting as the most grievous bug to impact Magento and Adobe Commerce platforms in the past two years.

The vulnerability has been assigned a critical CVSS score of 9.8, which underscores its significant potential for exploitation and the severe consequences it could have on businesses that depend on these platforms.

Adobe has promptly responded by issuing security upgrades for CVE-2024-34102. Nevertheless, nearly seventy-five percent of vulnerable websites have yet to implement these essential updates, despite the availability of patches.

Before applying the security updates, Sansec suggests that administrators configure their e-commerce platforms to operate in “Report-Only” mode.

Administrators and owners of e-commerce platforms are strongly encouraged to prioritize the installation of these security patches promptly in order to mitigate the risks associated with the vulnerability.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Grayscale Dogecoin ETF Makes Historic NYSE Trading Debut

November 24, 2025

Breaking: FBI Probes Cardano Network Split After Malicious Transaction

November 24, 2025

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

You might also like

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

1 Million WordPress Sites Affected by WPML Plugin Vulnerability

1 Million WordPress Sites Affected by WPML Plugin Vulnerability

CocoaPods Vulnerabilities from 2014 Endanger Millions of Apple Devices

CocoaPods Vulnerabilities from 2014 Endanger Millions of Apple Devices

BitcoinIRA Security Flaw Allows Hacker to Take Over User Accounts

BitcoinIRA Security Flaw Allows Hacker to Take Over User Accounts

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?