668
VMScore

CVE-2022-24108

Published: 17/05/2022 Updated: 26/05/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote malicious user to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

skyoftech so listing tabs 2.2.0

Exploits

OpenCart So Listing Tabs component versions 220 and below suffer from a deserialization vulnerability that can allow for arbitrary file writes ...