Magento Critical Security Advisory
The remote code execution (RCE) vulnerability, or “shoplift” bug, was reported by Check Point Software Technologies in late January 2015. It affects both Magento Enterprise Edition and Magento Community Edition and allows attackers to obtain control over a store and its sensitive data, including personal customer information. Magento issued a patch for this issue on February 9, 2015.
Read more