Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe · Commerce and Magento Open Source
Date added (CISA)
2024-07-17
Remediation due
2024-08-07
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.