CVE-2026-5331: OpenCart Extension Installer installer.php path traversal
A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5331?
CVE-2026-5331 is classified as a high severity vulnerability due to its potential for remote exploitation leading to unauthorized access.
How do I fix CVE-2026-5331?
To fix CVE-2026-5331, you should upgrade OpenCart to a version beyond 4.1.0.3 where the vulnerability is patched.
What component is affected by CVE-2026-5331?
CVE-2026-5331 affects the 'installer.php' file within the OpenCart Extension Installer Page component.
Can CVE-2026-5331 be exploited remotely?
Yes, CVE-2026-5331 can be exploited remotely, allowing an attacker to manipulate the file system.
In which version of OpenCart was CVE-2026-5331 identified?
CVE-2026-5331 was identified in OpenCart version 4.1.0.3.