CVE-2024-21518

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jun 22, 2024
Updated: Jul 3, 2024
CWE ID 22
CWE ID 29
CWE ID 290

Summary

CVE-2024-21518 is a newly discovered vulnerability affecting versions of the opencart/opencart package starting from 4.0.0.0. The issue stems from insufficient sanitization of the target path during installation via the marketplace, leading to a Zip Slip vulnerability. An attacker can exploit this weakness by inserting malicious files within ZIP archives, enabling them to traverse the filesystem and be extracted to arbitrary locations. Consequently, attackers can create new files in the web root or overwrite existing files, posing a serious risk to the application's security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-21518 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions