CVE-2024-21518
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-21518 is a newly discovered vulnerability affecting versions of the opencart/opencart package starting from 4.0.0.0. The issue stems from insufficient sanitization of the target path during installation via the marketplace, leading to a Zip Slip vulnerability. An attacker can exploit this weakness by inserting malicious files within ZIP archives, enabling them to traverse the filesystem and be extracted to arbitrary locations. Consequently, attackers can create new files in the web root or overwrite existing files, posing a serious risk to the application's security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenCart
Affected Vendors
- Opencart