CVE-2018-11495: Path Traversal
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the downloadid. For example, an attacker can download ../../config.php.
Other sources
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the downloadid. For example, an attacker can download ../../config.php.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-11495.
What is the severity of CVE-2018-11495?
The severity of CVE-2018-11495 is medium (4.9).
What is the affected software?
The affected software is Opencart version 3.0.2.0.
How does CVE-2018-11495 work?
CVE-2018-11495 allows directory traversal in the editDownload function, enabling an attacker to download files outside the intended directory.
Is there a fix for CVE-2018-11495?
Yes, a fix for CVE-2018-11495 is available. It is recommended to update Opencart to a version that has addressed this vulnerability.