VDB
Sign up
HIGH8.0

GHSA-xrh7-2gfq-4rcq

openCart Server-Side Template Injection (SSTI) vulnerability

Details

A Server-Side Template Injection (SSTI) vulnerability in the Theme Editor Function of openCart project v4.0.2.3 allows attackers to execute arbitrary code via injecting a crafted payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/opencart/opencart
Introduced in: 0

No fixed version published yet for opencart/opencart (composer). Pin to a known-safe version or switch to an alternative.

References