CyberSec.Space Logo
Back to CVE Browser

CVE-2024-34102

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-06-13
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Affected Platforms (CPE)

πŸ“¦
Adobe

Commerce

= 2.4.2= 2.4.3= 2.4.4= 2.4.5= 2.4.6= 2.4.7
πŸ“¦
Adobe

Commerce Webhooks

>= 1.2.0 and < 1.5.0
πŸ“¦
Adobe

Magento

= 2.4.4= 2.4.5= 2.4.6= 2.4.7

References & Advisories

Related Security Intelligence Articles

Related Vulnerabilities