CVE-2018-11494: Path Traversal
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving languageinfo['code'].
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this OpenCart vulnerability?
The vulnerability ID for this OpenCart vulnerability is CVE-2018-11494.
What is the severity of CVE-2018-11494?
The severity of CVE-2018-11494 is high.
How does the vulnerability in OpenCart through 3.0.2.0 occur?
The vulnerability in OpenCart through 3.0.2.0 occurs due to a six-step process in the program extension upload feature that allows attackers to execute arbitrary code.
How can an attacker exploit CVE-2018-11494?
An attacker can exploit CVE-2018-11494 by discovering a secret temporary directory name and executing arbitrary code if the remove step is skipped.
Is there a fix available for CVE-2018-11494?
Yes, there is a fix available for CVE-2018-11494. It is recommended to update OpenCart to a version beyond 3.0.2.0.