CVE-2024-34102
published 2024-06-13CVE-2024-34102: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE')…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2024-08-07
Exploited in the wild
EPSS
99.99%
100.0th percentile
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.4-p8 | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_webhooks | >= 1.2.0 < 1.5.0 | 1.5.0 |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| magento | community-edition | >= 0 < 2.4.4-p9 | 2.4.4-p9 |
| magento | community-edition | >= 2.4.5-p1 < 2.4.5-p8 | 2.4.5-p8 |
| magento | community-edition | >= 2.4.6-p1 < 2.4.6-p6 | 2.4.6-p6 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-34102 is exploited via crafted XML documents using PHP filters to read arbitrary files; chain with CVE-2024-2961 (glibc iconv buffer overflow) enables unauthenticated RCE. Detect anomalous XML requests containing PHP filter chains targeting Magento/Adobe Commerce endpoints. ↗
- →Threat actors steal Magento cryptographic (secret encryption) keys via CosmicSting; monitor for unauthorized reads of Magento configuration files (e.g., env.php) containing encryption keys. ↗
- →Malicious scripts are injected from domains masquerading as well-known JavaScript libraries or analytics packages (e.g., jQuery, CDN analytics); monitor outbound script loads from unexpected external domains on e-commerce checkout pages. ↗
- →ScreamedJungle threat actor injects Bablosoft JS into compromised Magento sites to harvest browser fingerprints using PerfectCanvas technology; detect unexpected Bablosoft JS script inclusions on Magento storefronts.
- →The exploit chain reads /proc/self/maps to leak PHP heap addresses and libc filename, then downloads the libc binary to extract offsets; detect HTTP requests to Magento endpoints that trigger file reads of /proc/self/maps or libc shared objects. ↗
- ·The exploit requires both CVE-2024-34102 (XXE) AND CVE-2024-2961 (glibc iconv buffer overflow) to achieve RCE; CVE-2024-34102 alone is an information disclosure / arbitrary file read. Vulnerable PHP versions span 7.0.0 through 8.3.7 and glibc 2.39 and earlier must also be present. ↗
- ·75% of the Adobe Commerce & Magento install base had not patched when automated scanning for secret encryption keys began, indicating widespread exposure; patching alone may be insufficient if keys were already exfiltrated — key rotation is also required. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
osv·2024-06-13
CVE-2024-34102 [CRITICAL] Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
GHSA
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
ghsa·2024-06-13
CVE-2024-34102 [CRITICAL] CWE-611 Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
VulnCheck
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-34102 [CRITICAL] CWE-611 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
Affected: Adobe Commerce and Magento Open Source
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sansec.io/research/cosmicsting-hitting-major-stores; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sansec.io/research/cosmicsting-cnext-persistent-backdoor; https://sansec.io/research/cosmicsting; https://sansec.io/research/cosmicsting-fallout; https://dashboard.sha
CISA
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
cisa·2024-07-17·CVSS 9.8
CVE-2024-34102 [CRITICAL] CWE-611 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Vulnerability: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Affected: Adobe Commerce and Magento Open Source
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/magento/apsb24-40.html; https://nvd.nist.gov/vuln/detail/CVE-2024-34102
Remediation Due Date: 2024-08-07
Suricata
ET WEB_SPECIFIC_APPS Adobe Commerce / Magento Pre-Authentication XML Entity Injection (CVE-2024-34102)
suricata·2024-09-26·CVSS 9.8
CVE-2024-34102 [CRITICAL] ET WEB_SPECIFIC_APPS Adobe Commerce / Magento Pre-Authentication XML Entity Injection (CVE-2024-34102)
ET WEB_SPECIFIC_APPS Adobe Commerce / Magento Pre-Authentication XML Entity Injection (CVE-2024-34102)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Adobe Commerce / Magento Pre-Authentication XML Entity Injection (CVE-2024-34102)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/rest/"; startswith; content:"/V1/guest-carts/"; distance:0; content:"/estimate-shipping-methods"; fast_pattern; endswith; http.content_type; content:"application/json"; http.header; to_lowercase; content:"x-requested-with|3a 20|xmlhttprequest|0d 0a|"; http.request_body; content:"|3c 21|DOCTYPE|20|"; content:"|3c 21|ELEMENT|20|"; distance:0; content:"|3c 21|ENTITY|20 25|"; distance:0; reference:url,www.assetnote.io/resources/research/why-nested-deserialization-is
Metasploit
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
metasploit·CVSS 7.3
CVE-2024-34102 [HIGH] CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
This combination of an Arbitrary File Read (CVE-2024-34102) and a Buffer Overflow in glibc (CVE-2024-2961) allows for unauthenticated Remote Code Execution on the following versions of Magento and Adobe Commerce and earlier if the PHP and glibc versions are also vulnerable: - 2.4.7 and earlier - 2.4.6-p5 and earlier - 2.4.5-p7 and earlier - 2.4.4-p8 and earlier Vulnerable PHP versions: - From PHP 7.0.0 (2015) to 8.3.7 (2024) Vulnerable iconv() function in the GNU C Library: - 2.39 and earlier The exploit chain is quite interesting and for more detailed information check out the references. The tl;dr being: CVE-2024-34102 is an XML External Entity vulnerability l
Nuclei
Adobe Commerce & Magento - CosmicSting
nuclei·CVSS 9.8
CVE-2024-34102 [CRITICAL] Adobe Commerce & Magento - CosmicSting
Adobe Commerce & Magento - CosmicSting
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution.
Template:
id: CVE-2024-34102
info:
name: Adobe Commerce & Magento - CosmicSting
author: DhiyaneshDK
severity: critical
description: |
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution.
impact: |
Unauthenticated attackers can exploit XXE to achieve arbitrary code execution on Adobe Commerce and Magento instances.
remediation: |
Update Adobe Commerce to version 2.4.7-p1, 2.4.6-p6
Metasploit
Magento XXE Unserialize Arbitrary File Read
metasploit
Magento XXE Unserialize Arbitrary File Read
Magento XXE Unserialize Arbitrary File Read
This module exploits a XXE vulnerability in Magento 2.4.7-p1 and below which allows an attacker to read any file on the system.
Bleepingcomputer
Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
blogs_bleepingcomputer·2024-10-03·CVSS 7.3
CVE-2024-34102 [HIGH] Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
## Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
## Bill Toulas
Adobe Commerce and Magento online stores are being targeted in "CosmicSting" attacks at an alarming rate, with threat actors hacking approximately 5% of all stores.
The CosmicSting vulnerability (CVE-2024-34102) is a critical severity information disclosure flaw; when chained with CVE-2024-2961, a security issue in glibc's iconv function, an attacker can achieve remote code execution on the target server.
The critical flaw impacts the following products:
Adobe Commerce 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Adobe Commerce Extended Support 2.4.3-ext-7 and earlier, 2.4.2-ext-7 and earlier, 2.4.1-ext-7 and earlier, 2.4.0-ext-7 and earlier, 2.3.7-p4-ext-7 and earlier.
Magento Open
Bleepingcomputer
Hackers inject malicious JS in Cisco store to steal credit cards, credentials
blogs_bleepingcomputer·2024-09-04·CVSS 9.8
[CRITICAL] Hackers inject malicious JS in Cisco store to steal credit cards, credentials
## Hackers inject malicious JS in Cisco store to steal credit cards, credentials
## Ionut Ilascu
Cisco’s site for selling company-themed merchandise is currently offline and under maintenance due to hackers compromising it with JavaScript code that steals sensitive customer details provided at checkout.
Cisco’s site for selling company-themed merchandise is currently offline and under maintenance due to a compromise with JavaScript code that steals sensitive details provided at checkout.
It is unclear how the malicious JavaScript landed on Cisco’s store but BleepingComputer has been told by researchers who wish to remain anonymous that it appears to be a CosmicSting attack ( CVE-2024-34102 ).
The Cisco Merchandise Store is a gift shop that provides Cisco-branded apparel and accessorie
Recorded Future
2024 Payment Fraud Report: Trends, Insights, and Predictions for 2025
blogs_recorded_future·CVSS 9.8
[CRITICAL] 2024 Payment Fraud Report: Trends, Insights, and Predictions for 2025
# Annual Payment Fraud Intelligence Report: 2024
## Summary
The 2024 Payment Fraud Intelligence Report from Recorded Future highlights a year of significant evolution in the fraud landscape, setting the stage for challenges in 2025. Key findings include a surge in stolen card data, with 269 million records posted across dark and clear web platforms, and a tripling of Magecart e-skimmer infections due to vulnerabilities like CosmicSting. Scam e-commerce and dark web card validation activities also saw notable increases, reflecting growing sophistication among threat actors.
Emerging trends indicate fraudsters’ increasing exploitation of modern payment technologies and social engineering to bypass anti-fraud measures. Predictions for 2025 include a rise in digital e-skimming and scam e-co
Greynoiseio
NoiseLetter July 2024
blogs_greynoiseio
NoiseLetter July 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
ScreamedJungle
threat_intel·CVSS 9.1
CVE-2024-34102 [CRITICAL] ScreamedJungle
# Threat Actor: ScreamedJungle
## Description
ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablosoft JS, into compromised websites. This actor has harvested millions of browser fingerprints by leveraging vulnerabilities such as CVE-2024-34102 and CVE-2024-20720. ScreamedJungle utilizes PerfectCanvas technology to ensure pixel-perfect replication of legitimate user fingerprints. Group-IB analysts estimate that over 115 e-commerce sites have been impacted by this fingerprint theft campaign.
Recorded Future
H1 2025 Malware and Vulnerability Trends
blogs_recorded_future
H1 2025 Malware and Vulnerability Trends
## H1 2025 Malware and Vulnerability Trends
## Executive Summary
The first half of 2025 (H1 2025) reflected a rapidly evolving threat landscape defined by the convergence of persistent legacy threats and advanced new tactics.
The total disclosed CVEs increased by 16% from H1 2024, and threat actors exploited 161 vulnerabilities with assigned CVEs, with nearly half linked to malware or ransomware campaigns. Microsoft remained the most targeted vendor, while edge security and gateway devices continued to be high-value targets for initial access. Malware activity was similarly dynamic: while law enforcement takedowns disrupted major players like LummaC2, a resurgence of legacy malware such as Sality indicated that old tools still offer utility for modern actors. Remote access trojans (RATs
Recorded Future
2024 Payment Fraud Report: Trends, Insights, and Predictions for 2025
blogs_recorded_future·CVSS 9.8
[CRITICAL] 2024 Payment Fraud Report: Trends, Insights, and Predictions for 2025
## Annual Payment Fraud Intelligence Report: 2024
## Summary
The 2024 Payment Fraud Intelligence Report from Recorded Future highlights a year of significant evolution in the fraud landscape, setting the stage for challenges in 2025. Key findings include a surge in stolen card data, with 269 million records posted across dark and clear web platforms, and a tripling of Magecart e-skimmer infections due to vulnerabilities like CosmicSting. Scam e-commerce and dark web card validation activities also saw notable increases, reflecting growing sophistication among threat actors.
Emerging trends indicate fraudsters’ increasing exploitation of modern payment technologies and social engineering to bypass anti-fraud measures . Predictions for 2025 include a rise in digital e-skimming and scam e-
Recorded Future
H1 2025 Malware and Vulnerability Trends
blogs_recorded_future
H1 2025 Malware and Vulnerability Trends
# H1 2025 Malware and Vulnerability Trends
## Executive Summary
The first half of 2025 (H1 2025) reflected a rapidly evolving threat landscape defined by the convergence of persistent legacy threats and advanced new tactics.
The total disclosed CVEs increased by 16% from H1 2024, and threat actors exploited 161 vulnerabilities with assigned CVEs, with nearly half linked to malware or ransomware campaigns. Microsoft remained the most targeted vendor, while edge security and gateway devices continued to be high-value targets for initial access. Malware activity was similarly dynamic: while law enforcement takedowns disrupted major players like LummaC2, a resurgence of legacy malware such as Sality indicated that old tools still offer utility for modern actors. Remote access trojans (RATs)
https://helpx.adobe.com/security/products/magento/apsb24-40.htmlhttps://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102https://helpx.adobe.com/security/products/magento/apsb24-40.htmlhttps://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-34102
2024-06-13
Published
2024-07-17
Added to CISA KEV
Exploited in the wild