HIGH7.2
GHSA-38f9-4vhq-9cr8
Zen Cart vulnerable to authenticated remote code execution
Quick fix
GHSA-38f9-4vhq-9cr8 — zencart/zencart: upgrade to the fixed version with the command below.
composer require zencart/zencart:^1.5.7cDetails
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zencart/zencart
Introduced in:
0Fixed in: 1.5.7cFix
composer require zencart/zencart:^1.5.7cReferences
- https://nvd.nist.gov/vuln/detail/CVE-2021-3291[ADVISORY]
- https://github.com/zencart/zencart/commit/7447627f7148b11c614f89dab4a09d3f102b58af[WEB]
- https://github.com/MucahitSaratar/zencart_auth_rce_poc[WEB]
- https://github.com/zencart/zencart[PACKAGE]
- http://packetstormsecurity.com/files/161613/Zen-Cart-1.5.7b-Remote-Code-Execution.html[WEB]