VDB
Sign up
HIGH7.2

GHSA-38f9-4vhq-9cr8

Zen Cart vulnerable to authenticated remote code execution

Quick fix

GHSA-38f9-4vhq-9cr8 — zencart/zencart: upgrade to the fixed version with the command below.

composer require zencart/zencart:^1.5.7c

Details

Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zencart/zencart
Introduced in: 0Fixed in: 1.5.7c
Fixcomposer require zencart/zencart:^1.5.7c

References