Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgj4-g5j4-cmfx

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction

cart2quote/module-quotation-encoded extension may expose a critical security vulnerability by utilizing the unserialize function when processing data from a GET request. This flaw, present in the app/code/community/Ophirah/Qquoteadv/controllers/DownloadController.php and app/code/community/Ophirah/Qquoteadv/Helper/Data.php files, poses a significant risk of Remote Code Execution, especially when custom file options are employed on a product. Attackers exploiting this vulnerability could execute arbitrary code remotely, leading to unauthorized access and potential compromise of sensitive data.

Пакеты

Наименование

cart2quote/module-quotation-encoded

composer
Затронутые версииВерсия исправления

>= 4.1.6, <= 4.4.5

Отсутствует

Наименование

cart2quote/module-quotation-encoded

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.4.4

5.4.4

7 High

CVSS3

Дефекты

CWE-94

7 High

CVSS3

Дефекты

CWE-94