Описание
Zen Cart vulnerable to authenticated remote code execution
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
Пакеты
Наименование
zencart/zencart
composer
Затронутые версииВерсия исправления
<= 1.5.7b
1.5.7c
Связанные уязвимости
CVSS3: 7.2
nvd
около 5 лет назад
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.