CVE-2024-34102
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
- Affected products
- Commerce
- Adobe Commerce
- = 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7
- Adobe Commerce Webhooks
- < 1.5.0
- Adobe Magento
- = 2.4.4, 2.4.5, 2.4.6, 2.4.7
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-611
- NVD status
- Analyzed
- Published
- 2024-06-13
CVE-2024-34102 at NVD
25 known exploits for CVE-2024-34102
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Adobe Commerce 2.4.7 XML Injection / Code Execution
Exploit for OS Command Injection in Aviatrix Controller
Magento / Adobe Commerce Remote Code Execution Exploit
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
Magento / Adobe Commerce Remote Code Execution
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Magento XXE Unserialize Arbitrary File Read
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Adobe Commerce / Magento Open Source XML Injection / User Impersonation
Magento XXE Unserialize Arbitrary File Read
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Code Injection in Geoserver
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce