In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.
Start learningUpgrade magento/core
to version 1.9.4.0 or higher.
magento/core is a release of the Magento Community Edition.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). An administrator on Magento 1 with permissions to update the Google Analytics configuration can trigger XSS vulnerability when another administrator issues a Credit Memo. This attack could allow one administrator to trigger privileged requests from another users account, changing further configuration or chaining together further attacks.