Executive brief
Adobe Commerce and Magento Open Source are vulnerable to an Improper Restriction of XML External Entity Reference (XXE). An unauthenticated remote attacker can exploit this by sending crafted XML documents to achieve arbitrary code execution without user interaction.
Affected products
- Adobe Commerce 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier
- Adobe Magento Open Source 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier
Timeline
- 2024-07-17: disclosed
- 2024-07-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog