Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx3q-f5f2-4q8v

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

OpenCart Path Traversal

The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].

Пакеты

Наименование

opencart/opencart

composer
Затронутые версииВерсия исправления

<= 3.0.2.0

Отсутствует

EPSS

Процентиль: 65%
0.005
Низкий

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
nvd
больше 7 лет назад

The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].

EPSS

Процентиль: 65%
0.005
Низкий

8 High

CVSS3

Дефекты

CWE-22