Website Security & Threat Management
New Magento WAF Rule – RCE Vulnerability Protection

New Magento WAF Rule – RCE Vulnerability Protection

4/25/2015 · Peter Dumanian

What this post added

Introduced a new ModSecurity rule to the Web Application Firewall (WAF) to protect against a specific Remote Code Execution (RCE) vulnerability in Magento versions 1.9.1.0 CE and 1.14.1.0 EE. This rule is available to customers using the WAF and requires manual enablement via the WAF Settings. The post also stresses the importance of users applying the SUPEE-5344 patch from Magento.

Read the original post ↗