cbcvebase.
CVE-2024-34102
published 2024-06-13

CVE-2024-34102: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE')…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-08-07
Exploited in the wild
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Affected

15 ranges
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.4-p8
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce_webhooks>= 1.2.0 < 1.5.01.5.0
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition>= 0 < 2.4.4-p92.4.4-p9
magentocommunity-edition>= 2.4.5-p1 < 2.4.5-p82.4.5-p8
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p62.4.6-p6

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL