CRITICAL

CVE-2024-34102

Adobe Commerce 2024-06-13 CVSS v3.1
CVSS
9.8
KEV

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

Summary dbcve.org

Adobe Commerce contains an Improper Restriction of XML External Entity Reference (XXE) vulnerability in its XML parsing functionality. Attackers can send crafted XML documents containing external entity references to achieve arbitrary code execution on the affected system. This critical flaw affects versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier, and can be exploited without any user interaction.

Mitigation

Apply the vendor-released security patch or upgrade to a supported Adobe Commerce version that addresses this XXE vulnerability. Additionally, configure XML parsers to disable external entity processing as a defense-in-depth measure.

Proof of Concept

Weakness (CWE)

CWE-611 XML External Entity (XXE)

EPSS Score

99.99%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE