Magento XXE CVE-2024-34102

Опубликовано: 05 Апрель 2026
на канале: National Cyber Secuirty Services
545
21

🔥Magento XXE CVE-2024-34102: A newly discovered vulnerability
dubbed “CosmicSting” jeopardizes millions of online stores
built on Adobe Commerce and Magento platforms.
⚠️CosmicSting enables attackers to gain unauthorized access
to sensitive files, including those containing passwords.
When combined with a recent Linux bug (CVE-2024-2961),
the vulnerability can be escalated to remote code execution.
📣Dorks:
Hunter: http://product.name="Adobe Magento"
FOFA: app="Adobe-Magento"
SHODAN: http.html:"magento-template"
🔴POC: https://github.com/th3gokul/CVE-2024-...
⚠️Tool Made By: D. Sanjai Kumar & Gokul V
#cybersecurity #cybersecurityawareness #security #informationsecurity #hacker #datasecurity #hacking #threat #infosecurity #technology #cloud #hacks #computerscience #informationtechnology #social #tech #hacked #android #bugbounty #OWASP #subdomain
ncybersecurity.com
+91-8016167754
  / nationalcybers1  
  / national-cyber-security-services  
Services: [email protected]
Training: [email protected]
National Cyber Security Services