CVE-2024-34102

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

9.8
CVSS 3.1
100.0 %
EPSS (current)
2024-07-17
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Adobe / Commerce and Magento Open Source

Published: 2024-06-13 · Due (CISA): 2024-08-07

CWE: CWE-611 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2024/CVE-2024-34102.yamlAdobe Commerce & Magento - CosmicSting–
metasploitauxiliary/gather/magento_xxe_cve_2024_34102auxiliary/gather/magento_xxe_cve_2024_341022024-06-11
metasploitexploit/linux/http/magento_xxe_to_glibc_buf_overflowexploit/linux/http/magento_xxe_to_glibc_buf_overflow2024-07-26

References only — no downloads or instructions.

Sources