Sploitus

CVE-2024-34102

25 known exploits for CVE-2024-34102

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Affected products
Commerce
Adobe Commerce
= 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7
Adobe Commerce Webhooks
< 1.5.0
Adobe Magento
= 2.4.4, 2.4.5, 2.4.6, 2.4.7
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
100.0% (100th percentile)
Weakness
CWE-611
NVD status
Analyzed
Published
2024-06-13
CVE-2024-34102 at NVD
Authoritative description, scoring and affected products

25 known exploits for CVE-2024-34102

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2026-05-25 russellwork2021-lgtmGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2026-02-13 nmmoretteGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2025-08-14 Kento-SecGITHUB
Adobe Commerce 2.4.7 XML Injection / Code Execution
2025-01-13 EQSTLabPACKETSTORM
Exploit for OS Command Injection in Aviatrix Controller
2025-01-12 th3gokulGITHUB
Magento / Adobe Commerce Remote Code Execution Exploit
2024-10-22 metasploitZDTRuby
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
2024-10-18 Sergey Temnikov, Charles Fol, Heyder, jheysel-r7METASPLOITRuby
Magento / Adobe Commerce Remote Code Execution
2024-10-18 Charles FOL, jheysel-r7, Heyder, Sergey Temnikov, metasploit.comPACKETSTORMRuby
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-10-08 bkaGITHUB
Magento XXE Unserialize Arbitrary File Read
2024-08-31 Heyder, Sergey Temnikov, metasploit.comPACKETSTORMRuby
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-08-19 JhonsonwannaaGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-08-19 dream434GITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-08-13 EQSTSeminarGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-08-13 EQSTLabGITHUB
Adobe Commerce / Magento Open Source XML Injection / User Impersonation
2024-07-22 RedWay Security, github.comPACKETSTORM
Magento XXE Unserialize Arbitrary File Read
2024-07-18 Sergey Temnikov, HeyderMETASPLOITRuby
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-07-13 bughuntarGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-07-07 SamJUKGITHUB
Exploit for Code Injection in Geoserver
2024-07-05 RevoltSecuritiesGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-07-01 jakabakosGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-06-30 0x0d3adGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-06-28 11whoami99GITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-06-28 d0rbGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-06-28 ChocapikkGITHUB
Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce
2024-06-27 bigb0xGITHUB