An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
extension xml bug magento2 patch hotfix xxe xml-security security-hole xml-entity cosmicsting cve-2024-34102 cosmic-sting
- Updated
Feb 6, 2025 - PHP