OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
References
| Link | Resource |
|---|---|
| https://github.com/A3h1nt/CVEs/blob/main/OpenCart/Readme.md | Exploit Third Party Advisory |
| https://github.com/PawaritSanguanpang/CVEs/blob/main/OpenCart/CVE-2024-36694/README.md | Exploit Third Party Advisory |
| https://github.com/opencart/opencart/issues/13863 | Issue Tracking Vendor Advisory |
| https://github.com/opencart/opencart/releases/tag/4.0.2.3 | Product |
| https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 | Exploit Third Party Advisory |
| https://medium.com/@pawarit.sanguanpang/opencart-v4-0-2-3-server-side-template-injection-0b173a3bdcf9 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-12-18 20:15
Updated : 2025-04-22 15:36
NVD link : CVE-2024-36694
Mitre link : CVE-2024-36694
CVE.ORG link : CVE-2024-36694
JSON object : View
Products Affected
opencart
- opencart
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
