Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affecting opencart/opencart package, versions >=0.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.09% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-OPENCARTOPENCART-6673151
  • published 24 Apr 2024
  • disclosed 14 May 2022
  • credit Unknown

How to fix?

There is no fixed version for opencart/opencart.

Overview

opencart/opencart is a shopping cart system

Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') due to improper input validation in the editDownload function in admin\model\catalog\download.php. An attacker can access arbitrary files on the server by manipulating the download_id parameter in the request to admin/index.php?route=catalog/download/edit, leading to the download of sensitive files such as ../../config.php.