Skip to content
Blog

Security Vulnerability in xt:Commerce

14 February 2009 | INGATE Team

A critical security vulnerability has been discovered in the e-commerce software xt:Commerce that allows attackers to gain unauthorized access to online shops.

Affected Versions

Multiple versions of xt:Commerce are affected. We recommend all operators check their version and update immediately.

Type of Vulnerability

The security vulnerability allows:

  • SQL injection via certain parameters
  • Access to the database containing customer data
  • In the worst case: administrator access to the shop

Immediate Actions

  1. Update xt:Commerce to the latest version
  2. Check your database for unauthorized changes
  3. Change all admin passwords
  4. Review server logs for suspicious access attempts

Managed Server Customers

If you operate a managed server with INGATE and use xt:Commerce, contact us. We will assist you with securing your system.

Contact: info@ingate.de

Technology Partners & Memberships

Dell PartnerDirect
Equinix
EMC Home of Data
Juniper Networks
LiveConfig
Microsoft Cloud Solution Provider
Microsoft SPLA Partner
RIPE NCC Member