First published: Thu Aug 31 2017(Updated: )
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenCart | <=2.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10509 has a medium severity rating due to its potential for SQL injection by authenticated administrators.
To fix CVE-2016-10509, upgrade OpenCart to version 2.3.0.0 or higher.
CVE-2016-10509 affects remote authenticated administrators using OpenCart versions prior to 2.3.0.0.
CVE-2016-10509 is classified as an SQL injection vulnerability in OpenCart.
CVE-2016-10509 impacts the updateAmazonOrderTracking function in OpenCart.