, 15 2017 . 22:07
+
Magento, , ,
Magento 2.1.9, 2.0.16, XSS, CSRF, , / .
Magento 1.x, 1.9.3.6 1.14.3.6 .
/ .
: .
(1)
APPSEC-1800: Remote Code Execution vulnerability in CMS and layouts
: , .
layout, .
- Magento 1.x , .
- - .
(3)
APPSEC-1887 , .
APPSEC-1850 - ,
APPSEC-1851 RCE , .
(29)
APPSEC-1567 , -, cookie.
APPSEC-1769 sitemap
APPSEC-1713
APPSEC-1852 XSS CSRF XSS CSRF
APPSEC-1482
APPSEC-1502 XSS
APPSEC-1494 XSS - xml xml.
APPSEC-1793 CRE Nginx
APPSEC-1819 ,
APPSEC-1802 CSRF
APPSEC-1493 XSS
APPSEC-1755 CSRF
APPSEC-1853 XSS CSRF
APPSEC-1729 XSS
APPSEC-1591 XSS
APPSEC-1896 XSS
APPSEC-1673 XSS SVG favicon
APPSEC-1773 DoS ID
APPSEC-1577 XSS
APPSEC-1510 favicon
APPSEC-1545 XSS
APPSEC-1535 .
APPSEC-1588
APPSEC-1701 API
APPSEC-1630
APPSEC-1628
APPSEC-1599 - -
(2)
APPSEC-1709
APPSEC-1495
, Magento 1.x.
APPSEC-1793 ngin .
APPSEC-1588 .
, , .
, , X, , X. , .
X .
, .
18 35 , .
-, .
1. , .
2. ,
.
:
https://magento.com/security/patches/magento-2016-and-219-security-update
:
2.015-2.0.16 2.1.8-2.1.9
: .

https://habrahabr.ru/post/338052/
:
author kirmorozov
e-commerce
open source
magento
magento 2
-
xss
csrf