CVE-2024-21519

June 22, 2024, 5:15 a.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

opencart

  • 4.0.0.0

Source

report@snyk.io

Tags

CVE-2024-21519 details

Published : June 22, 2024, 5:15 a.m.
Last Modified : June 22, 2024, 5:15 a.m.

Description

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code into the database, an attacker with admin privileges can create a backup file with an arbitrary filename (including the extension), within /system/storage/backup. **Note:** It is less likely for the created file to be available within the web root, as part of the security recommendations for the application suggest moving the storage path outside of the web root.

CVSS Score

1 2 3 4 5 6.6 7 8 9 10

Weakness

Weakness Name Description
CWE-20 Improper Input Validation The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

6.6

Exploitability Score

0.7

Impact Score

5.9

Base Severity

MEDIUM

This website uses the NVD API, but is not approved or certified by it.