OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
References
Link | Resource |
---|---|
https://github.com/A3h1nt/CVEs/blob/main/OpenCart/Readme.md | Exploit Third Party Advisory |
https://github.com/PawaritSanguanpang/CVEs/blob/main/OpenCart/CVE-2024-36694/README.md | Exploit Third Party Advisory |
https://github.com/opencart/opencart/issues/13863 | Issue Tracking Vendor Advisory |
https://github.com/opencart/opencart/releases/tag/4.0.2.3 | Product |
https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 | Exploit Third Party Advisory |
https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 | Exploit Third Party Advisory |
Configurations
History
22 Apr 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/A3h1nt/CVEs/blob/main/OpenCart/Readme.md - Exploit, Third Party Advisory | |
References | () https://github.com/PawaritSanguanpang/CVEs/blob/main/OpenCart/CVE-2024-36694/README.md - Exploit, Third Party Advisory | |
References | () https://github.com/opencart/opencart/issues/13863 - Issue Tracking, Vendor Advisory | |
References | () https://github.com/opencart/opencart/releases/tag/4.0.2.3 - Product | |
References | () https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:opencart:opencart:4.0.2.3:*:*:*:*:*:*:* | |
First Time |
Opencart
Opencart opencart |
23 Jan 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 Dec 2024, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
References | () https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 - |
18 Dec 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-18 20:15
Updated : 2025-04-22 15:36
NVD link : CVE-2024-36694
Mitre link : CVE-2024-36694
CVE.ORG link : CVE-2024-36694
JSON object : View
Products Affected
opencart
- opencart
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')