⚠ Actively exploited
Added to CISA KEV on 2024-07-17. Federal agencies required to patch by 2024-08-07. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-34102

Severity
9.8CRITICAL
EPSS
94.1%
top 0.09%
CISA KEV
KEV
Added 2024-07-17
Due 2024-08-07
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 13
KEV addedJul 17
KEV dueAug 7
Latest updateOct 3
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

NVDadobe/commerce_webhooks1.2.01.5.0
CVEListV5adobe/adobe_commerce2.4.4-p8
NVDadobe/commerce6 versions+5
NVDadobe/magento4 versions+3
Packagistmagento/community-edition2.4.6-p12.4.6-p6+2

🔴Vulnerability Details

4
OSV
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability2024-06-13
GHSA
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability2024-06-13
CVEList
XXE can expose crypt key and other secrets granting full admin access2024-06-13
VulnCheck
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability2024

💥Exploits & PoCs

2
Metasploit
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
Nuclei
Adobe Commerce & Magento - CosmicSting

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Adobe Commerce / Magento Pre-Authentication XML Entity Injection (CVE-2024-34102)2024-09-26

📋Vendor Advisories

1
CISA
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability2024-07-17

🕵️Threat Intelligence

3
Bleepingcomputer
Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks2024-10-03
Bleepingcomputer
Hackers inject malicious JS in Cisco store to steal credit cards, credentials2024-09-04
Threat Intel
ScreamedJungle
CVE-2024-34102 (CRITICAL CVSS 9.8) | Adobe Commerce versions 2.4.7 | cvebase.io