CVE-2024-34102 (CRITICAL) CVSS 9.8
🔴 Severity: CRITICAL (CVSS 9.8)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference (‘XXE’) vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Published: 2024-06-13
Last Modified: 2025-10-23 ⚠️
References:
- helpx.adobe.com/security/…
- www.vicarius.io/vsociety/…
- helpx.adobe.com/security/…
- www.vicarius.io/vsociety/…
- www.cisa.gov/known-exp…