Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...

Wild Exploitation of Critical Flaw in Adobe Commerce and Magento

Red | Vulnerability Report
Download PDF

A critical unauthenticated XXE (XML External Entity) vulnerability has been discovered in Adobe Commerce and Magento, identified as CVE-2024-34102. This flaw, assigned a CVSS score of 9.8, is due to improper restriction of XML external entity references. The vulnerability allows attackers to execute arbitrary code by sending a crafted XML document that references external entities. Exploiting this issue does not require user interaction, and the vulnerability is actively being exploited in attacks.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox