← back
CVE-2024-34102criticalunder attackCWE-611

XXE can expose crypt key and other secrets granting full admin access

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon14 days
Published on NVDJun 13
1st PoC+14d
metasploitJun 11
CISA KEV+34d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
40 public exploit(s)
Action required by CISAfederal deadline: 2024-08-07

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · Adobe Commerce
public PoCs found40
githubgithub.com/Chocapikk/CVE-2024-3410248githubgithub.com/bigb0x/CVE-2024-3410231githubgithub.com/th3gokul/CVE-2024-3410214githubgithub.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento9githubgithub.com/bughuntar/CVE-2024-341025githubgithub.com/EQSTLab/CVE-2024-341024githubgithub.com/11whoami99/CVE-2024-341023githubgithub.com/0x0d3ad/CVE-2024-341022githubgithub.com/wubinworks/magento2-cosmic-sting-patch1githubgithub.com/Phantom-IN/CVE-2024-341021githubgithub.com/nmmorette/CVE-2024-341021githubgithub.com/Kento-Sec/CVE-2024-341020githubgithub.com/russellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit0githubgithub.com/ArturArz1/TestCVE-2024-341020githubgithub.com/d0rb/CVE-2024-341020githubgithub.com/cmsec423/CVE-2024-341020githubgithub.com/cmsec423/Magento-XXE-CVE-2024-341020githubgithub.com/SamJUK/cosmicsting-validator0githubgithub.com/unknownzerobit/poc0githubgithub.com/crynomore/CVE-2024-341020githubgithub.com/dream434/CVE-2024-341020githubgithub.com/bka/magento-cve-2024-34102-exploit-cosmicstring0githubgithub.com/wubinworks/magento2-encryption-key-manager-cli0githubgithub.com/Koray123-debug/CVE-2024-341020vulncheckvulncheck.com/xdb/68297a933a3cunverifiedvulncheckvulncheck.com/xdb/62c07de93469unverifiedvulncheckvulncheck.com/xdb/e10072b9959aunverifiedvulncheckvulncheck.com/xdb/e16ac34e34d7unverifiedvulncheckvulncheck.com/xdb/f7ec53083d00unverifiedvulncheckvulncheck.com/xdb/56d612cb301bunverifiedvulncheckvulncheck.com/xdb/b740eaf30da0unverifiedvulncheckvulncheck.com/xdb/ff651d9ccadfunverifiedvulncheckvulncheck.com/xdb/b9a5654f364dunverifiedvulncheckvulncheck.com/xdb/2eb4d44dc79bunverifiedvulncheckvulncheck.com/xdb/18320f3f459cunverifiedvulncheckvulncheck.com/xdb/771b0f9ad8b9unverifiedvulncheckvulncheck.com/xdb/31319adbe12aunverifiedvulncheckvulncheck.com/xdb/60b0937b5f4funverifiedvulncheckvulncheck.com/xdb/dc00179a0cb9unverifiedvulncheckvulncheck.com/xdb/034f54dfbdb8unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.