PT-2024-4170 · Adobe · Commerce
Jakaba01
·
Published
2024-06-11
·
Updated
2025-09-21
·
CVE-2024-34102
CVSS v2.0
10
10
Critical
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier
Description
The vulnerability is related to an improper restriction of XML external entity references, which could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. The exploitation of this issue does not require user interaction. It is estimated that over 4,000 e-stores have been compromised by exploiting this vulnerability, with 5% of Adobe Commerce and Magento stores being affected. The vulnerability has been used by hackers to inject malicious scripts and steal sensitive customer information, including payment card data.
Recommendations
For Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier, update to a version that is not affected by the vulnerability.
As a temporary workaround, consider disabling the XML external entity reference feature until a patch is available.
Restrict access to the vulnerable module to minimize the risk of exploitation.
Rotate encryption keys to prevent further attacks.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2024-04655
BIT-MAGENTO-2024-34102
CVE-2024-34102
GHSA-M8CJ-3V68-3CXJ
Affected Products
Commerce
References · 144
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb⭐ 35834 🔗 14382 · Exploit
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/magento_xxe_cve_2024_34102.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2024-34102.yaml⭐ 2049 🔗 306 · Exploit
- 🔥 https://github.com/Chocapikk/CVE-2024-34102⭐ 40 🔗 10 · Exploit
- 🔥 https://github.com/bigb0x/CVE-2024-34102⭐ 28 🔗 9 · Exploit
- 🔥 https://github.com/th3gokul/CVE-2024-34102⭐ 13 🔗 1 · Exploit
- 🔥 https://github.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento⭐ 6 🔗 1 · Exploit
- 🔥 https://github.com/bughuntar/CVE-2024-34102⭐ 3 🔗 2 · Exploit
- 🔥 https://github.com/EQSTLab/CVE-2024-34102⭐ 3 · Exploit
- 🔥 https://vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102 · Exploit
- https://osv.dev/vulnerability/CVE-2024-34102 · Vendor Advisory
- https://bdu.fstec.ru/vul/2024-04655 · Security Note
- https://osv.dev/vulnerability/GHSA-m8cj-3v68-3cxj · Vendor Advisory
- https://osv.dev/vulnerability/BIT-magento-2024-34102 · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/709866 · Security Note