Arbitrary Code Execution in OpenCart by Authenticated Users
CVE-2023-47444
8.8HIGH
What is CVE-2023-47444?
A security issue has been identified in OpenCart versions 4.0.0.0 to 4.0.2.3 that allows authenticated backend users with specific write privileges to inject untrusted data into critical configuration files, namely config.php and admin/config.php. This flaw potentially enables these users to execute arbitrary code on the server, posing a severe security threat. Proper patches and mitigations are essential to protect installations from unauthorized access and exploitation.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved