Magento E-Commerce and Vtiger CRM Specialist

Latest Magento 1 security updates for 90,000 online stores

The latest security updates for Magento Commerce 1 and Magento Open Source 1 fix two vulnerabilities that could allow an attacker to execute arbitrary code and allow an attacker to steal sensitive information.

Adobe has rolled out the latest security updates for Web store software Magento 1, meaning that more than 90,000 to 99,000 Web stores will no longer receive patches. Newly discovered vulnerabilities will no longer be fixed by the software company. This puts online stores that continue to use Magento 1 at greater risk of attacks.

There are two versions of Magento 1 in circulation, Magento Commerce and Magento Open Source. According to measurement website SimilarTech, there are over 99,000 Web shops using Magento 1. Built With comes out to about 90,000 websites. In the past, vulnerabilities in Magento have regularly been used by criminals to add malicious code to websites in order to steal customers' personal and credit card information.

Also, the latest security updates for Magento Commerce 1 and Magento Open Source 1 fix two vulnerabilities that allow this to happen. These are PHP Object Injection that allows an attacker to execute arbitrary code and stored cross-site scripting that allows an attacker to steal sensitive information. In the case of these two vulnerabilities, however, an attacker must already have administrator privileges to exploit them.

As recently as April, online stores were alerted by credit card company Visa to the end of support for Magento 1. According to the company, online stores that continue to use Magento 1 are no longer compliant with the Payment Card Industry Data Security Standards (PCI DSS), an international security standard that defines how to handle customer payment card data. Web stores that want to remain PCI-compliant are advised by Visa to migrate to a platform that is still supported with security updates.

source: Security.co.uk

Make your Magento 1 webshop PCI DSS compliant

Trust Guard How It Works BannerTogether with Trust Guard, we offer a subscription to keep your shop PCI DSS compliant. Trust Guard performs regular scans on the shop and reports all findings to Vicus. Vicus resolves them in consultation with the hosting party. When all findings are resolved, Trust Guard issues a PCS DSS certificate for your shop. With this you can convince your PSP that your webshop meets the PCI DSS requirements.