CVE-2024-34102
| CVE Published | 2024-06-13 |
|---|---|
| Related CWE(s) | CWE-611: Improper Restriction of XML External Entity Reference |
| Related Vendor(s) | adobe |
| Related Product(s) | magento, commerce, commerce_webhooks |
| Exploitation Reported (CISA KEV) | 2024-07-17 |
| CVSS 3 Base Score | 9.8 (CRITICAL) |
| CVSS 3 Attack Complexity | LOW |
| CVSS 3 Attack Vector | NETWORK |
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph