CVE-2024-34102
CVE Published | 2024-06-13 |
---|---|
Related CWE(s) | CWE-611: Improper Restriction of XML External Entity Reference |
Related Vendor(s) | adobe |
Related Product(s) | commerce_webhooks, magento, commerce |
Exploitation Reported (CISA KEV) | 2024-07-17 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph