CVE-2024-34102
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
- Affected products
- Commerce
- Adobe Commerce
- = 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7
- Adobe Commerce Webhooks
- < 1.5.0
- Adobe Magento
- = 2.4.4, 2.4.5, 2.4.6, 2.4.7
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-611
- NVD status
- Analyzed
- Published
- 2024-06-13
CVE-2024-34102 at NVD
48 known exploits for CVE-2024-34102
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102
magento2-encryption-key-manager-cli
magento2-cosmic-sting-patch
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102
cosmicsting-validator
magento-cve-2024-34102-exploit-cosmicstring
cosmicsting-cve-2024-34102-exploit
CVE-2024-36401
CVE-2024-34102
CVE-2024-34102
CVE-2024-34102
Vmware-ESXI
CVE-2024-34102
TestCVE-2024-34102
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Adobe Commerce 2.4.7 XML Injection / Code Execution
Exploit for OS Command Injection in Aviatrix Controller
Magento / Adobe Commerce Remote Code Execution Exploit
Magento / Adobe Commerce Remote Code Execution
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Magento XXE Unserialize Arbitrary File Read
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
Adobe Commerce / Magento Open Source XML Injection / User Impersonation
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Code Injection in Geoserver
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
Magento XXE Unserialize Arbitrary File Read