CVE-2024-21518

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations. An attacker can create arbitrary files in the web root of the application and overwrite other existing files by exploiting this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*

History

24 Jun 2024, 19:56

Type Values Removed Values Added
CPE cpe:2.3:a:opencart:opencart:*:*:*:*:*:*:*:*
CWE CWE-22
References () https://github.com/opencart/opencart/blob/04c1724370ab02967d3b4f668c1b67771ecf1ff4/upload/admin/controller/marketplace/installer.php%23L383C1-L383C1 - () https://github.com/opencart/opencart/blob/04c1724370ab02967d3b4f668c1b67771ecf1ff4/upload/admin/controller/marketplace/installer.php%23L383C1-L383C1 - Patch
References () https://security.snyk.io/vuln/SNYK-PHP-OPENCARTOPENCART-7266578 - () https://security.snyk.io/vuln/SNYK-PHP-OPENCARTOPENCART-7266578 - Exploit, Third Party Advisory
First Time Opencart opencart
Opencart
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

22 Jun 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-22 05:15

Updated : 2024-07-03 01:46


NVD link : CVE-2024-21518

Mitre link : CVE-2024-21518


JSON object : View

Products Affected

opencart

  • opencart
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')