{"id":533,"date":"2020-11-23T22:28:11","date_gmt":"2020-11-23T22:28:11","guid":{"rendered":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/"},"modified":"2020-11-23T22:28:13","modified_gmt":"2020-11-23T22:28:13","slug":"securite-magento-reste-en-proie-aux-injections-sql","status":"publish","type":"post","link":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/","title":{"rendered":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL"},"content":{"rendered":"<p>[ad_1]<br \/>\n <br \/>La derni\u00e8re mise \u00e0 jour de s\u00e9curit\u00e9 pour Magento corrige une faille critique qui peut permettre \u00e0 des tiers de prendre le contr\u00f4le de sites e-commerce.<br \/>\nComment acheter une montre de luxe pour trois fois rien ? En piratant un site e-commerce.<br \/>\nCheck Point avait, voil\u00e0 plus de quatre ans, choisi cette approche pour communiquer sur une faille que deux de ses chercheurs avaient d\u00e9couverte dans Magento.<br \/>\nLa plate-forme e-commerce appartenait alors encore \u00e0 eBay (qui l\u2019a depuis lors c\u00e9d\u00e9e, Adobe s\u2019en emparant finalement pour pr\u00e8s de 2 milliards de dollars).<br \/>\nLa faille en question permettait d\u2019acc\u00e9der aux bases de donn\u00e9es des sites e-commerce. Et par l\u00e0 m\u00eame, entre autres, de cr\u00e9er des comptes administrateurs\u2026 en capacit\u00e9 notamment de changer le prix de tout article.<br \/>\nL\u2019acc\u00e8s aux bases de donn\u00e9es se faisait par injection SQL.<br \/>\n\u00c7a s\u2019en va et \u00e7a revient<br \/>\nCe type de vuln\u00e9rabilit\u00e9 \u2013 qui ne touche pas toujours la plate-forme en elle-m\u00eame \u2013 est r\u00e9guli\u00e8rement recens\u00e9 sur Magento.<br \/>\nIl vient de faire l\u2019objet d\u2019un nouveau correctif, publi\u00e9 cette semaine sous la r\u00e9f\u00e9rence PRODSECBUG-2198.<br \/>\nPr\u00e9sente aussi bien dans la version open source de Magento que dans la version commerciale, la faille qu\u2019\u00e9limine ce correctif affiche un haut score de criticit\u00e9 : 9\/10. L\u2019exploiter ne requiert pas d\u2019authentification et le processus peut facilement \u00eatre automatis\u00e9.<br \/>\nApr\u00e8s \u00e9tude du correctif, Sucuri (fournisseur am\u00e9ricain de solutions de s\u00e9curit\u00e9) sugg\u00e8re aux utilisateurs de Magento de v\u00e9rifier leurs journaux de connexion. Un grand nombre d\u2019acc\u00e8s \u00e0 l\u2019entr\u00e9e \/catalog\/product\/frontend_action_synchronize est susceptible de refl\u00e9ter une attaque.<br \/>\nD\u2019autres failles pr\u00e9sentant un score de criticit\u00e9 sup\u00e9rieur \u00e0 9\/10 sont corrig\u00e9es pour l\u2019occasion. L\u2019une d\u2019entre elles permet \u00e0 un utilisateur authentifi\u00e9 et disposant des droits ad\u00e9quats d\u2019ins\u00e9rer du code malveillant dans des mod\u00e8les d\u2019e-mails ou de newsletters.<\/p>\n<p>[ad_2]<br \/>\n <br \/><a href=\"https:\/\/www.itespresso.fr\/securite-magento-injections-sql-204979.html\">\u0421\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] La derni\u00e8re mise \u00e0 jour de s\u00e9curit\u00e9 pour Magento corrige une faille critique qui peut permettre \u00e0 des tiers de prendre le contr\u00f4le de sites e-commerce. Comment acheter une montre de luxe pour trois fois rien ? En piratant un site e-commerce. Check Point avait, voil\u00e0 plus de quatre ans, choisi cette approche pour [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":534,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualites-marketing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World\" \/>\n<meta property=\"og:description\" content=\"[ad_1] La derni\u00e8re mise \u00e0 jour de s\u00e9curit\u00e9 pour Magento corrige une faille critique qui peut permettre \u00e0 des tiers de prendre le contr\u00f4le de sites e-commerce. Comment acheter une montre de luxe pour trois fois rien ? En piratant un site e-commerce. Check Point avait, voil\u00e0 plus de quatre ans, choisi cette approche pour [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\" \/>\n<meta property=\"og:site_name\" content=\"Hot News in World\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-23T22:28:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-11-23T22:28:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"771\" \/>\n\t<meta property=\"og:image:height\" content=\"579\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"hotnewsinworld\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"hotnewsinworld\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\"},\"author\":{\"name\":\"hotnewsinworld\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b\"},\"headline\":\"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL\",\"datePublished\":\"2020-11-23T22:28:11+00:00\",\"dateModified\":\"2020-11-23T22:28:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\"},\"wordCount\":346,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg\",\"articleSection\":[\"ACTUALIT\u00c9S MARKETING\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\",\"url\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\",\"name\":\"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World\",\"isPartOf\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg\",\"datePublished\":\"2020-11-23T22:28:11+00:00\",\"dateModified\":\"2020-11-23T22:28:13+00:00\",\"author\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b\"},\"breadcrumb\":{\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage\",\"url\":\"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg\",\"contentUrl\":\"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg\",\"width\":771,\"height\":579,\"caption\":\"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/hotnewsinworld.com\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/#website\",\"url\":\"https:\/\/hotnewsinworld.com\/fr\/\",\"name\":\"Hot News in World\",\"description\":\"Hot News in World France\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/hotnewsinworld.com\/fr\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b\",\"name\":\"hotnewsinworld\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g\",\"caption\":\"hotnewsinworld\"},\"url\":\"https:\/\/hotnewsinworld.com\/fr\/author\/jacob\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/","og_locale":"fr_FR","og_type":"article","og_title":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World","og_description":"[ad_1] La derni\u00e8re mise \u00e0 jour de s\u00e9curit\u00e9 pour Magento corrige une faille critique qui peut permettre \u00e0 des tiers de prendre le contr\u00f4le de sites e-commerce. Comment acheter une montre de luxe pour trois fois rien ? En piratant un site e-commerce. Check Point avait, voil\u00e0 plus de quatre ans, choisi cette approche pour [&hellip;]","og_url":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/","og_site_name":"Hot News in World","article_published_time":"2020-11-23T22:28:11+00:00","article_modified_time":"2020-11-23T22:28:13+00:00","og_image":[{"width":771,"height":579,"url":"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg","type":"image\/jpeg"}],"author":"hotnewsinworld","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"hotnewsinworld","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#article","isPartOf":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/"},"author":{"name":"hotnewsinworld","@id":"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b"},"headline":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL","datePublished":"2020-11-23T22:28:11+00:00","dateModified":"2020-11-23T22:28:13+00:00","mainEntityOfPage":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/"},"wordCount":346,"commentCount":0,"image":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage"},"thumbnailUrl":"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg","articleSection":["ACTUALIT\u00c9S MARKETING"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/","url":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/","name":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL - Hot News in World","isPartOf":{"@id":"https:\/\/hotnewsinworld.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage"},"image":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage"},"thumbnailUrl":"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg","datePublished":"2020-11-23T22:28:11+00:00","dateModified":"2020-11-23T22:28:13+00:00","author":{"@id":"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b"},"breadcrumb":{"@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#primaryimage","url":"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg","contentUrl":"https:\/\/hotnewsinworld.com\/fr\/wp-content\/uploads\/sites\/12\/2020\/11\/Securite-Magento-reste-en-proie-aux-injections-SQL.jpg","width":771,"height":579,"caption":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL"},{"@type":"BreadcrumbList","@id":"https:\/\/hotnewsinworld.com\/fr\/securite-magento-reste-en-proie-aux-injections-sql\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/hotnewsinworld.com\/fr\/"},{"@type":"ListItem","position":2,"name":"S\u00e9curit\u00e9 : Magento reste en proie aux injections SQL"}]},{"@type":"WebSite","@id":"https:\/\/hotnewsinworld.com\/fr\/#website","url":"https:\/\/hotnewsinworld.com\/fr\/","name":"Hot News in World","description":"Hot News in World France","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hotnewsinworld.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/hotnewsinworld.com\/fr\/#\/schema\/person\/83a544fee3543ca6cac3e25ac03a3c2b","name":"hotnewsinworld","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/dfb5c469893235b3ffc8a5339f3396fccf74700b0e409a20d7c915a0bb844606?s=96&d=mm&r=g","caption":"hotnewsinworld"},"url":"https:\/\/hotnewsinworld.com\/fr\/author\/jacob\/"}]}},"_links":{"self":[{"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/posts\/533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/comments?post=533"}],"version-history":[{"count":1,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/posts\/533\/revisions"}],"predecessor-version":[{"id":535,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/posts\/533\/revisions\/535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/media\/534"}],"wp:attachment":[{"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/media?parent=533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/categories?post=533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hotnewsinworld.com\/fr\/wp-json\/wp\/v2\/tags?post=533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}