.. / CVE-2024-34102

Exploit for Adobe Commerce & Magento < 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 - Unauthenticated XML External Entity (CVE-2024-34102)

Description:

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference (‘XXE’) vulnerability that could result in arbitrary code execution.

Affected Products:

Proof of Concept

PoC exploit

Nuclei Template

View the template here CVE-2024-34102.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2024/CVE-2024-34102.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2024-34102
https://github.com/spacewasp/public_docs/blob/main/CVE-2024-34102.md
https://www.assetnote.io/resources/research/why-nested-deserialization-is-harmful-magento-xxe-cve-2024-34102