OpenCart Zero-Day Vulnerability Allows Arbitrary File Overwrite
CVE-2024-21518
What is CVE-2024-21518?
The vulnerability in OpenCart's marketplace installer allows attackers to exploit a Zip Slip issue caused by improper sanitization of target paths. This flaw enables files within a malicious archive to traverse the filesystem, resulting in the extraction of arbitrary files to unintended locations. Through this vulnerability, an attacker can potentially create or overwrite files in the web root of OpenCart applications, posing serious security risks. It is crucial for affected users to address this flaw promptly to protect their systems from unauthorized access and data manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opencart/opencart 4.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
