Web Hack List

Collected research

Why nested deserialization is harmful: Magento XXE (CVE-2024-34102)

Shows how Magento's recursive, type-directed REST deserialization can instantiate an unexpected SimpleXMLElement object. Crafted nested input reaches XML parsing and enables unauthenticated XXE with file disclosure and broader compromise potential.

Record

Researcher
Shubham Shah
Published by
slcyber.io

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Shubham Shah, first published at the original source. Preserved copies are kept so the citation survives its host.