Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2v2-3784-vr44

Опубликовано: 18 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-xrh7-2gfq-4rcq. This link is maintained to preserve external references.

Original Description

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

Пакеты

Наименование

opencart/opencart

composer
Затронутые версииВерсия исправления

<= 4.0.2.3

Отсутствует

7.2 High

CVSS3

Дефекты

CWE-94

7.2 High

CVSS3

Дефекты

CWE-94