CyberSec.Space Logo
CVEブラウザに戻る

CVE-2024-34102

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-06-13
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Affected Platforms (CPE)

📦
Adobe

Commerce

= 2.4.2= 2.4.3= 2.4.4= 2.4.5= 2.4.6= 2.4.7
📦
Adobe

Commerce Webhooks

>= 1.2.0 and < 1.5.0
📦
Adobe

Magento

= 2.4.4= 2.4.5= 2.4.6= 2.4.7

References & Advisories

関連するセキュリティ記事

関連する脆弱性情報