CVE-2024-34110: RCE in the Adobe Commerce Webhook module through a legit webhook definition
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. A high-privilege attacker could exploit this vulnerability by uploading a malicious file to the system, which could then be executed. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34110?
CVE-2024-34110 is categorized as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-34110?
To fix CVE-2024-34110, upgrade your Adobe Commerce version to the latest patched release.
What is an Unrestricted Upload of File with Dangerous Type in CVE-2024-34110?
The Unrestricted Upload of File with Dangerous Type in CVE-2024-34110 allows high-privilege attackers to upload potentially malicious files to the server.
Which versions of Adobe Commerce are affected by CVE-2024-34110?
CVE-2024-34110 affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8, and earlier versions.
What could an attacker achieve by exploiting CVE-2024-34110?
If exploited, an attacker could execute arbitrary code on the server, potentially compromising the entire Adobe Commerce environment.