CVE-2023-26691

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 22

Summary

CVE-2023-26691 is a directory traversal vulnerability affecting CS-Cart MultiVendor version 4.16.1. Attackers can exploit this flaw by uploading a maliciously crafted zip file during the installation of a new add-on. Successful exploitation enables the attacker to run arbitrary code, potentially leading to serious security implications such as data theft or unauthorized system access. Users are advised to upgrade to a secure version of CS-Cart MultiVendor as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • CS-Cart Multi-Vendor

Affected Vendors

  • CS-Cart