PT-2024-4170 · Adobe · Commerce
Jakaba01
·
Published
2024-06-11
·
Updated
2025-11-20
·
CVE-2024-34102
CVSS v2.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Adobe Commerce and Magento Open Source
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected.
Description
Adobe Commerce and Magento Open Source are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. This issue could allow an attacker to execute arbitrary code by sending a crafted XML document referencing external entities. The vulnerability is actively exploited, with reports indicating over 4,000 stores have been compromised and approximately 5% of Adobe Commerce and Magento stores are affected. Multiple threat actors are actively exploiting this flaw, injecting malicious scripts. The vulnerability allows attackers to steal data and potentially compromise cryptographic keys used for authentication. The
app/etc/env.php file, containing sensitive cryptographic keys, is potentially exposed through exploitation. The vulnerability does not require user interaction for exploitation.Recommendations
Upgrade to a version later than 2.4.7-p1 to address this vulnerability.
Exploit
Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2024-04655
BIT-MAGENTO-2024-34102
CVE-2024-34102
GHSA-M8CJ-3V68-3CXJ
Affected Products
Commerce
References · 146
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb⭐ 36906 🔗 14618 · Exploit
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/magento_xxe_cve_2024_34102.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2024-34102.yaml⭐ 2049 🔗 306 · Exploit
- 🔥 https://github.com/Chocapikk/CVE-2024-34102⭐ 40 🔗 10 · Exploit
- 🔥 https://github.com/bigb0x/CVE-2024-34102⭐ 28 🔗 9 · Exploit
- 🔥 https://github.com/th3gokul/CVE-2024-34102⭐ 13 🔗 1 · Exploit
- 🔥 https://github.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento⭐ 6 🔗 1 · Exploit
- 🔥 https://github.com/bughuntar/CVE-2024-34102⭐ 3 🔗 2 · Exploit
- 🔥 https://github.com/EQSTLab/CVE-2024-34102⭐ 3 · Exploit
- 🔥 https://vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102 · Exploit
- https://osv.dev/vulnerability/CVE-2024-34102 · Vendor Advisory
- https://osv.dev/vulnerability/GHSA-m8cj-3v68-3cxj · Vendor Advisory
- https://helpx.adobe.com/security/products/magento/apsb24-40.html · Security Note, Vendor Advisory
- https://bdu.fstec.ru/vul/2024-04655 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/709866 · Security Note