Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why is BL_CustomGrid not included in the list? #28

Closed
AlterWeb opened this issue Mar 28, 2019 · 6 comments · Fixed by #48
Closed

Why is BL_CustomGrid not included in the list? #28

AlterWeb opened this issue Mar 28, 2019 · 6 comments · Fixed by #48

Comments

@AlterWeb
Copy link
Collaborator

It is mentioned in https://gwillem.gitlab.io/2018/10/23/magecart-extension-0days/

@gwillem
Copy link
Collaborator

gwillem commented Mar 28, 2019

I wasn't entirely certain that BL_CustomGrid is vulnerable or that attackers were trying to exploit it. Additional info welcome!

@AlterWeb
Copy link
Collaborator Author

AlterWeb commented Apr 1, 2019

@gwillem Thank you for your response. If I have some time in the near future I will have a look at it to determine if I can find a way to exploit it. I thought you already did so I disabled this module for some clients but did noticed that it was not being reported while enabled at a new clients Magento store.

@jissereitsma
Copy link
Contributor

Does the following link help? https://www.cybersecurity-help.cz/vdb/SB2018102411?affChecked=1

@NikoGrano
Copy link
Contributor

I can take this. I'm preparing anyways a PR here about one other vuln. Also I'm currently going trough this BL.

@NikoGrano
Copy link
Contributor

Currently working on this, will open PR and publish blog post today.

@NikoGrano
Copy link
Contributor

Waiting #48 to pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants