Magento 電商平台遭駭客利用 SVG 圖檔側錄交易資料
資安公司 Sansec 發現大規模 Magecart 感染,駭客利用 Magento 漏洞在電商網站植入 1x1 像素的 SVG 圖檔以隱藏金融卡側錄程式。受害者在偽造的結帳頁面輸入資料後會被導向真實網頁,導致交易資訊在不知不覺中遭竊取。
All Coverage
1 original reportsThe Backstory
The history behind this eventCritical RCE Flaw in Magento Extension Affects More Than 6,000 Online Stores
Magento and Adobe Commerce merchants commonly use Mirasvit Cache Warmer to prebuild full-page caches and speed up storefront loading. Sansec found that the extension passed user-controlled data to PHP’s unserialize() function, creating an object-injection vulnerability. Unauthenticated attackers could remotely execute code, putting transaction data and control of affected servers at risk.
Sansec discovered the vulnerability on April 24, 2026, and Mirasvit released version 1.11.12 to patch it on May 25. It was designated CVE-2026-45247 the following day and received a CVSS 3.1 score of 9.8. Sansec scanned more than 6,000 stores using Mirasvit extensions. The U.S. Cybersecurity and Infrastructure Security Agency confirmed exploitation on June 3 and added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to address it by June 6.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.