Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wg5-m6pq-5x5g

Опубликовано: 29 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

EPSS

Процентиль: 37%
0.00162
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 года назад

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

EPSS

Процентиль: 37%
0.00162
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-20