CVE-2024-36694: Code Injection
A Server-Side Template Injection (SSTI) vulnerability in the Theme Editor Function of openCart project v4.0.2.3 allows attackers to execute arbitrary code via injecting a crafted payload.
Other sources
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36694?
CVE-2024-36694 is classified as a critical severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-36694?
To mitigate CVE-2024-36694, you should upgrade OpenCart to a version later than 4.0.2.3 where the vulnerability has been patched.
What type of vulnerability is CVE-2024-36694?
CVE-2024-36694 is a Server-Side Template Injection (SSTI) vulnerability.
Which version of OpenCart is affected by CVE-2024-36694?
CVE-2024-36694 affects OpenCart version 4.0.2.3 specifically.
Can CVE-2024-36694 be exploited remotely?
Yes, CVE-2024-36694 can be exploited remotely, allowing attackers to execute arbitrary code from an external source.