HIGH8.0
GHSA-xrh7-2gfq-4rcq
openCart Server-Side Template Injection (SSTI) vulnerability
Details
A Server-Side Template Injection (SSTI) vulnerability in the Theme Editor Function of openCart project v4.0.2.3 allows attackers to execute arbitrary code via injecting a crafted payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/opencart/opencart
Introduced in:
0No fixed version published yet for opencart/opencart (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-36694[ADVISORY]
- https://github.com/opencart/opencart/issues/13863[WEB]
- https://github.com/A3h1nt/CVEs/blob/main/OpenCart/Readme.md[WEB]
- https://github.com/opencart/opencart[PACKAGE]
- https://github.com/opencart/opencart/releases/tag/4.0.2.3[WEB]
- https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9[WEB]