Magento Security Patch – SUPEE 6285
A new critical Magento security patch has been released to secure the platform from potential attacks. There are no confirmed reports of attacks related to these issues to-date, but it is important to immediately deploy the patch in order to protect online store. This patch prevents attackers from posing as an administrator to gain access to the last orders feed, which contains personally identifiable information that can then be used to obtain more sensitive information in follow-on attacks and closes a number of security gaps including cross-site scripting (XSS), cross-site request forgery (CSRF), and error path disclosure vulnerabilities.