VYPR
Critical severityCISA KEVNVD Advisory· Published Jun 13, 2024· Updated Oct 21, 2025

XXE can expose crypt key and other secrets granting full admin access

CVE-2024-34102

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
>= 2.4.6-p1, < 2.4.6-p62.4.6-p6
magento/community-editionPackagist
>= 2.4.5-p1, < 2.4.5-p82.4.5-p8
magento/community-editionPackagist
< 2.4.4-p92.4.4-p9

Affected products

3

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.