OpenCart Zero-Day Vulnerability Allows Arbitrary File Overwrite
CVE-2024-21518

7.2HIGH

Key Information:

Vendor
opencart
Vendor
CVE Published:
22 June 2024

Summary

The vulnerability in OpenCart's marketplace installer allows attackers to exploit a Zip Slip issue caused by improper sanitization of target paths. This flaw enables files within a malicious archive to traverse the filesystem, resulting in the extraction of arbitrary files to unintended locations. Through this vulnerability, an attacker can potentially create or overwrite files in the web root of OpenCart applications, posing serious security risks. It is crucial for affected users to address this flaw promptly to protect their systems from unauthorized access and data manipulation.

Affected Version(s)

opencart/opencart 4.0.0.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Calum Hutton
.