Magento – Webgility RCE vulnerability

magento-1.9Securitythird-party-module

MageReport.com reported today that they released a new check concerning a recently discovered backdoor in the module Webgility.

While their tool is very helpful in scanning the site and asserting whether our site is vulnerable or not, they do not provide steps for fixing the issue.

Does anyone know what the vulnerability is and what immediate steps can be taken besides for disabling the module?
To the best of my knowledge, Webgility has not released an updated module.

UPDATE

So, it turns out that as per Willem de Groot's post – webgility was made aware of the flaw and are apparently not taking it seriously.

The fix according to Willem is to restrict access to the webgility directory to recognized IP addresses.

Best Answer

We have released the patch of Webgility Store Module. Please refer our blog for complete details. https://www.webgility.com/blog/security-vulnerability-update/

Related Topic