← back
CVE-2024-21518highCWE-22CWE-29CWE-290

CVE-2024-21518

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 14%
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
In short

OpenCart's marketplace installer has a flaw that lets attackers extract files from malicious archives to any location on the server, potentially overwriting important files or adding malicious code to the website.

Technical detail

A path traversal vulnerability in OpenCart 4.0.0.0+ allows attackers to craft malicious ZIP archives that bypass sanitization checks during extraction via the marketplace installer, enabling arbitrary file creation and overwriting in the web root. The attacker must be able to upload or trigger installation of a malicious marketplace extension. Impact includes code execution through file placement in web-accessible directories.

Summary generated and translated by AI from the official description.
This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations. An attacker can create arbitrary files in the web root of the application and overwrite other existing files by exploiting this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P
Affected products
n/a · opencart/opencart