Magecart Attackers Pioneer Persistent E-Commerce Backdoor
ID: 8dcc38b0-f66a-54f1-b48f-909d32ee3135
STIX ID: report--8dcc38b0-f66a-54f1-b48f-909d32ee3135
Feed Name: Dark Reading
Threat Score
Sansec researchers observed Magecart operators exploiting a critical Magento command injection (CVE-2024-20720, CVSS 9.1) that allows attackers to store XML layout templates as persistent backdoors in the layout_update table; the backdoor executes on /checkout/cart and injects a Stripe payment skimmer that captures and exfiltrates payment data. Adobe has patched the issue—e-tailers should upgrade to 2.4.6-p4, 2.4.5-p6, or 2.4.4-p7 to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
