Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affecting opencart/opencart package, versions >=4.0.0.0
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.1% (43rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-OPENCARTOPENCART-5922105
- published 28 Sep 2023
- disclosed 27 Sep 2023
- credit Poh Jia Hao
Introduced: 27 Sep 2023
CVE-2023-2315 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
opencart/opencart is a shopping cart system
Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') via the 'Log' component. An attacker can empty out arbitrary files on the server.
Note:
This vulnerability can be exploited when the attacker has a set of valid credentials to the backend dashboard with access
and modify
permissions on tool/log
.
References
CVSS Scores
version 3.1