Patch Patch Patch!

edmondscommerce

Free Member
Nov 11, 2008
3,651
628
UK
Another important patch with a major security vulnerability has been realeased.

Unfortunately they have managed to make it incompatible with one of their previous patches (doh!)

https://magento.com/security/patches/supee-8788

It needs applying ASAP though as it includes both a remote code execution and an SQL injection vulnerability along with a host of other security fixes.

Any one of the fixes would warrant an urgent patch, all of them together make this a bit of a whopper. The people who are actively exploiting Magento on a large scale probably already have working exploits to take advantage of these so time is of the essence.

Make sure you have up to date backups of your site

Get yourself patched ASAP

Getting hacked is no fun
 
By the way, pay attention to the last sentence on the patch page:

Be sure to implement and test the patch in a development environment first to confirm that it works as expected before deploying it to a production site.
 
Upvote 0

Latest Articles