CVE-2021-3291: OS Command Injection
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3291?
CVE-2021-3291 has been assigned a high severity rating due to its ability to allow arbitrary OS command execution.
How does CVE-2021-3291 affect Zen Cart 1.5.7b?
CVE-2021-3291 allows unauthorized users to execute arbitrary OS commands through the admin interface of Zen Cart 1.5.7b.
How do I mitigate CVE-2021-3291?
To mitigate CVE-2021-3291, it is recommended to upgrade to a patched version of Zen Cart or implement stricter access controls.
What are the potential impacts of CVE-2021-3291 on my system?
Exploitation of CVE-2021-3291 could lead to complete system compromise, unauthorized access, and potential data loss.
Are there any known exploits for CVE-2021-3291?
Yes, there are known proof-of-concept exploits for CVE-2021-3291 that demonstrate how to execute arbitrary commands.