GHSA-pgj4-g5j4-cmfx
cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction
Quick fix
GHSA-pgj4-g5j4-cmfx — cart2quote/module-quotation-encoded: upgrade to the fixed version with the command below.
composer require cart2quote/module-quotation-encoded:^5.4.4Details
cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.1.6No fixed version published yet for cart2quote/module-quotation-encoded (composer). Pin to a known-safe version or switch to an alternative.
5.0.0Fixed in: 5.4.4composer require cart2quote/module-quotation-encoded:^5.4.4References
- https://bitbucket.org/cart2quote2/cart2quote2-releases[PACKAGE]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/cart2quote/module-quotation/2017-02-01.yaml[WEB]
- https://web.archive.org/web/20230131172111/https://cart2quote.zendesk.com/hc/en-us/articles/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction[WEB]