CVE-2024-34102
KEVCRITICAL 9.8EPSS 100.0%
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.99% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-07-17
- Nuclei
- critical · CWE-611
- Published
- 2024-06-13
- Updated
- 2025-10-21
Proof-of-concept exploits (23)
- https://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerabi…
- 0x0d3ad/CVE-2024-341022★ · 2024-07-01
- 11whoami99/CVE-2024-341023★ · 2024-07-01
- ArturArz1/TestCVE-2024-341020★ · 2024-06-27
- Chocapikk/CVE-2024-3410248★ · 2024-09-05
- EQSTLab/CVE-2024-341025★ · 2025-01-12
- EQSTSeminar/CVE-2024-341025★ · 2025-01-12
- Kento-Sec/CVE-2024-341020★ · 2025-08-14
- Koray123-debug/CVE-2024-341020★ · 2025-05-11
- Phantom-IN/CVE-2024-341021★ · 2024-07-14
- RevoltSecurities/CVE-2024-364011★ · 2024-07-05
- bigb0x/CVE-2024-3410231★ · 2024-06-29
- bka/magento-cve-2024-34102-exploit-cosmicstring0★ · 2024-10-09
- bughuntar/CVE-2024-341025★ · 2024-07-15
- cmsec423/CVE-2024-341020★ · 2024-07-01
- crynomore/CVE-2024-341020★ · 2024-07-11
- d0rb/CVE-2024-341020★ · 2024-06-28
- dream434/CVE-2024-341020★ · 2025-02-22
- jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento9★ · 2024-07-05
- mksundaram69/CVE-2024-341020★ · 2025-01-07
- th3gokul/CVE-2024-3410214★ · 2025-01-12
- nmmorette/CVE-2024-34102
- russellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit