CVE-2024-21518

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jun 22, 2024
Updated: Jul 3, 2024
CWE ID 22
CWE ID 29
CWE ID 290

Summary

CVE-2024-21518 is a newly discovered vulnerability affecting versions of the opencart/opencart package starting from 4.0.0.0. The issue stems from insufficient sanitization of the target path during installation via the marketplace, leading to a Zip Slip vulnerability. An attacker can exploit this weakness by inserting malicious files within ZIP archives, enabling them to traverse the filesystem and be extracted to arbitrary locations. Consequently, attackers can create new files in the web root or overwrite existing files, posing a serious risk to the application's security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share