CVE-2016-10509: SQL Injection
Published Aug 31, 2017
·Updated
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courierid) parameter to openbay.php.
Affected Software
1 affected component
OpenCart OpenCart<=2.3.0.0
Remediation
Event History
Aug 31, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10509?
CVE-2016-10509 has a medium severity rating due to its potential for SQL injection by authenticated administrators.
2
How do I fix CVE-2016-10509?
To fix CVE-2016-10509, upgrade OpenCart to version 2.3.0.0 or higher.
3
Who is affected by CVE-2016-10509?
CVE-2016-10509 affects remote authenticated administrators using OpenCart versions prior to 2.3.0.0.
4
What type of vulnerability is CVE-2016-10509?
CVE-2016-10509 is classified as an SQL injection vulnerability in OpenCart.
5
What functions are impacted by CVE-2016-10509?
CVE-2016-10509 impacts the updateAmazonOrderTracking function in OpenCart.