VDB
Sign up
HIGH7.0

GHSA-pgj4-g5j4-cmfx

cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction

Quick fix

GHSA-pgj4-g5j4-cmfx — cart2quote/module-quotation-encoded: upgrade to the fixed version with the command below.

composer require cart2quote/module-quotation-encoded:^5.4.4

Details

cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cart2quote/module-quotation-encoded
Introduced in: 4.1.6

No fixed version published yet for cart2quote/module-quotation-encoded (composer). Pin to a known-safe version or switch to an alternative.

Packagist/cart2quote/module-quotation-encoded
Introduced in: 5.0.0Fixed in: 5.4.4
Fixcomposer require cart2quote/module-quotation-encoded:^5.4.4

References